CVE-2026-10033
Received Received - Intake

Authorization Bypass in EventON Action User WordPress Plugin

Vulnerability report for CVE-2026-10033, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: Wordfence

Description

The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to grant EventON management capabilities and the upload_files capability to any non-administrator WordPress role or user, escalating their privileges within the site. The administrator role is protected by an early-return guard in update_role_caps(), so only non-administrator roles and individual users can be targeted; however, the same unauthenticated exposure also allows attackers to enumerate all WordPress users with their IDs and display names, disclose role and user capability state along with nonce values, and tamper with event-to-user term assignments.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
eventon eventon_action_user to 2.5.14 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The EventON Action User plugin for WordPress has an authorization bypass flaw in versions up to 2.5.14. It fails to verify user permissions before allowing actions, letting unauthenticated attackers grant elevated capabilities to non-admin users. This includes management roles and file upload permissions. Attackers can also enumerate user details, view role capabilities, and modify event assignments.

Detection Guidance

To detect this vulnerability, check for unauthorized privilege escalation in WordPress. Look for unexpected changes in user roles or capabilities, especially non-administrator roles gaining management capabilities. Review logs for unusual activity related to the EventON Action User plugin. Use WordPress admin tools to audit user roles and capabilities.

Impact Analysis

If you use the vulnerable plugin, attackers could take over your WordPress site by escalating their privileges. They might gain control over event management, upload malicious files, or manipulate site content. User data could be exposed, and site integrity compromised without requiring authentication.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Unauthorized privilege escalation may result in data breaches, triggering compliance violations and potential legal penalties.

Mitigation Strategies

Update the EventON Action User plugin to the latest version beyond 2.5.14 to patch the authorization bypass vulnerability.

Review WordPress user roles and capabilities for any unauthorized changes, especially non-administrator roles that may have gained elevated privileges.

Check for suspicious user activity or unauthorized event-to-user term assignments in the WordPress admin panel.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10033. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart