CVE detail
CVE-2026-7537
The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type, extension, or MIME type validation being performed on uploaded files. This makes it possible for authenticated attackers, with administrator-level access and above, to upload files that may be executable, which makes remote code execution possible.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
11 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 1, 2026 to June 7, 2026)Wordfence
6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password' 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-8206 Patch Status Patched Published Jun 1, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researcher CHOIGYEONGMIN More Details > Multiple ShapedPlugin Plugins Support Board Gravit
vendorwww.wordfence.comJun 11, 2026, 5:13 PM - https://www.wordfence.com/threat-intel/vulnerabilities/id/42f37a41-deff-4b17-94d8-4e0fd1ce22c2?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJun 6, 2026, 4:17 AM - https://ryankozak.com/posts/cve-2026-7537/ryankozak.com
No excerpt available.
Exploitryankozak.comJun 6, 2026, 4:17 AM - https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3528037%40mobile-dj-manager&new=3528037%40mobile-dj-manager&sfp_email=&sfph_mail=plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 6, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/mobile-dj-manager/trunk/includes/admin/communications/comms-functions.php#L248plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 6, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/mobile-dj-manager/trunk/includes/admin/communications/comms-functions.php#L241plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 6, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/mobile-dj-manager/tags/1.7.8.3/includes/admin/communications/comms-functions.php#L248plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 6, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/mobile-dj-manager/tags/1.7.8.3/includes/admin/communications/comms-functions.php#L241plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 6, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/mobile-dj-manager/tags/1.7.8.2/includes/admin/communications/comms-functions.php#L248plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 6, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/mobile-dj-manager/tags/1.7.8.2/includes/admin/communications/comms-functions.php#L241plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 6, 2026, 4:17 AM - https://github.com/d0n601/CVE-2026-7537github.com
No excerpt available.
Exploitgithub.comJun 6, 2026, 4:17 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-24727CVSS 9.3 · Critical
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote au…
- CVE-2026-65461CVSS 9.1 · Critical
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
- CVE-2026-65455CVSS 9.1 · Critical
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
- CVE-2026-27064CVSS 9.1 · Critical
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
- CVE-2026-14282CVSS 9.8 · Critical
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versio…
- CVE-2026-63048CVSS 9.4 · Critical
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload,…