CyberRota Analysis
AI-GeneratedThe MDJM Event Management and Mobile Events Manager plugins for WordPress are vulnerable to unauthorized post deletions due to a lack of capability checks, nonces, and record type validation. This flaw allows unauthenticated attackers to permanently delete any post, page, or media attachment, leading to potential data loss and disruption. WordPress site administrators using these plugins should prioritize immediate updates to versions 1.7.8.5 and 1.4.8.4 or later to mitigate this risk.
Original NVD Description
The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.