What is CVE-2026-15017?
A Privilege Escalation vulnerability exists in MDJM Event Management plugin for WordPress up to version 1.7.8.4. Missing capability checks and nonce verification in `set_permissions()` and `init()` functions allow authenticated users to gain administrative access. Immediate update to the latest patched version is recommended.
Azərbaycanca: MDJM Event Management WordPress plugin-inin 1.7.8.4-ə qədər versiyalarında imtiyaz artırma zəifliyi aşkarlanıb. `set_permissions()` və `init()` funksiyalarında capability yoxlaması və nonce təsdiqi olmadığı üçün autentifikasiyalı istifadəçi administrator hüquqları əldə edə bilər. Plugin-i dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the MDJM Event Management plugin are affected by CVE-2026-15017?
This Privilege Escalation vulnerability affects all versions of the MDJM Event Management plugin up to 1.7.8.4.
How can I protect against the CVE-2026-15017 vulnerability?
It is recommended to immediately update the MDJM Event Management plugin to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.