A vulnerability classified as problematic was found in MDJM Event Management Plugin up to 1.7.8.4 on WordPress. This affects the function
MDJM_Permissions::set_permissions/MDJM_Employee_Manager::init/mdjm_set_employee_role/WP_User::set_role of the component Role Manipulation Endpoint. Executing a manipulation of the argument employee_roles[]/new_role can lead to permission issues.
This vulnerability is tracked as CVE-2026-15017. The attack can be launched remotely. No exploit exists.