216.73.216.226

CVE-2026-7537

· Published 06/06/2026 04:17 · Modified 06/06/2026 04:17

Labels: CVE-2026-7537 2026-06-06CVE-2026-7537CWE-434[email protected]

Essential information

Published
06/06/2026 04:17
Modified
06/06/2026 04:17
Author
Creator
CVSS
7.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type, extension, or MIME type validation being performed on uploaded files. This makes it possible for authenticated attackers, with administrator-level access and above, to upload files that may be executable, which makes remote code execution possible.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mdjm / event management plugin cpe:2.3:a:mdjm:event_management_plugin:*:*:*:*:*:wordpress:*:*

References