7.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Description
The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type, extension, or MIME type validation being performed on uploaded files. This makes it possible for authenticated attackers, with administrator-level access and above, to upload files that may be executable, which makes remote code execution possible.
Basic Information
ID
CVE-2026-7537
Source
Wordfence
Published
Jun 6, 2026 at 02:28
Affected Product
Vendor
mdjm
Product
MDJM Event Management
Affected Versions
mdjm MDJM Event Management 0
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/42f37a41-deff-4b17-94d8-4e0fd1ce22c2
- plugins.trac.wordpress.org /browser/mobile-dj-manager/trunk/includes/admin/communications/comms-functions.php
- plugins.trac.wordpress.org /browser/mobile-dj-manager/tags/1.7.8.3/includes/admin/communications/comms-functions.php
- plugins.trac.wordpress.org /browser/mobile-dj-manager/trunk/includes/admin/communications/comms-functions.php
- plugins.trac.wordpress.org /browser/mobile-dj-manager/tags/1.7.8.3/includes/admin/communications/comms-functions.php
- plugins.trac.wordpress.org /browser/mobile-dj-manager/tags/1.7.8.2/includes/admin/communications/comms-functions.php
- plugins.trac.wordpress.org /browser/mobile-dj-manager/tags/1.7.8.2/includes/admin/communications/comms-functions.php
- github.com /d0n601/CVE-2026-7537
- ryankozak.com /posts/cve-2026-7537/
- plugins.trac.wordpress.org /changeset