CVE-2026-15017

WordPress · MDJM Event Management

The MDJM Event Management plugin for WordPress suffers from an improper privilege management vulnerability, allowing authenticated users to escalate their privileges.

Executive summary

A critical privilege escalation vulnerability in the MDJM Event Management plugin for WordPress, rated as High severity, allows authenticated users to gain unauthorized administrative access.

Vulnerability

This vulnerability is classified as CWE-269 (Improper Privilege Management). It allows an attacker who already possesses low-level authenticated access to the system to escalate their permissions, potentially gaining full control over the plugin functions.

Business impact

With a CVSS score of 8.8, this vulnerability poses a severe risk to business operations. Unauthorized privilege escalation can lead to total system compromise, including the exfiltration of sensitive event data, unauthorized financial transactions, or complete site takeover.

Remediation

Immediate Action: Update the MDJM Event Management plugin to version 1.7.8.5 or later immediately.

Proactive Monitoring: Monitor site traffic and database logs for suspicious queries originating from low-privileged accounts that attempt to access restricted administrative functions.

Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to block unauthorized requests to the plugin's administrative API endpoints.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The high CVSS score underscores the urgency of this remediation. All organizations utilizing the MDJM Event Management plugin must apply the vendor-supplied update immediately to prevent unauthorized privilege escalation and maintain the security of their web environment.