
PEACH
Un framework di isolamento del tenant
CVE-2026-88802 is an unauthenticated arbitrary post deletion vulnerability affecting the MDJM Event Management and Mobile Events Manager WordPress plugins. The flaw allows unauthenticated attackers to permanently delete arbitrary posts, pages, and media attachments by exploiting missing authorization checks in the playlist entry removal functionality. Affected versions include MDJM Event Management before 1.7.8.5 and Mobile Events Manager through 1.4.8.3. It was publicly disclosed on September 11, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (WPScan, Github Advisory).
The root cause is classified as CWE-862 (Missing Authorization). The vulnerable playlist entry removal endpoint fails to verify any capability, nonce, or record type before processing a deletion request, meaning no authentication or privilege is required to trigger a permanent post deletion. An attacker can send a crafted network request directly to this endpoint, specifying any post ID, and the plugin will permanently delete the targeted content without moving it to the WordPress trash, making recovery impossible. A proof-of-concept is scheduled for public release on October 11, 2026, to allow time for users to update (WPScan, Github Advisory).
Successful exploitation allows an unauthenticated remote attacker to permanently and irrecoverably destroy arbitrary WordPress posts, pages, and media attachments on affected sites, bypassing the trash mechanism entirely. The integrity impact is high, as site content can be wiped without any authentication, but there is no confidentiality or availability impact in the traditional sense. This could result in significant data loss, defacement, or disruption of business operations for event management companies relying on these plugins (WPScan, Github Advisory).
There is currently no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported. WPScan has indicated a PoC will be published on October 11, 2026. The EPSS score is approximately 0.233% (14th percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and no threat actor attribution has been made (WPScan, Github Advisory).
/wp-json/wp/v2/posts).wp-admin/admin-ajax.php with the appropriate action parameter and the target post ID), without supplying any authentication token or nonce.wp-admin/admin-ajax.php with action parameters associated with MDJM or Mobile Events Manager playlist removal functions, originating from unexpected or external IP addresses.post_status = 'trash').DELETE or status-change operations on wp_posts records not initiated by authenticated admin users.Update the MDJM Event Management WordPress plugin to version 1.7.8.5 or later, which contains the fix. For Mobile Events Manager, no fixed version is currently available (the plugin remains vulnerable through 1.4.8.3); site owners should consider deactivating or removing the plugin until a patch is released. As interim mitigations, implement Web Application Firewall (WAF) rules to block unauthenticated requests to the playlist entry removal AJAX endpoint, and restrict access to wp-admin/admin-ajax.php at the network or server level where feasible (WPScan, Github Advisory).
The vulnerability was discovered and reported by researchers Enrico Marcolini, Claudio Marchesini, and Dottor Marc, and was verified by WPScan. Wordfence included it in their weekly WordPress vulnerability report for the period of September 7–13, 2026. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability aggregator coverage (WPScan).
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."