Authorization Bypass Vulnerability in EventON Action User Plugin for WordPress
CVE-2026-10033

7.3HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 July 2026

What is CVE-2026-10033?

The EventON Action User plugin for WordPress is affected by a significant vulnerability that allows unauthorized users to bypass normal access controls. This flaw enables an unauthenticated attacker to grant themselves management capabilities within the plugin, including the ability to upload files, thereby escalating their privileges without proper authorization checks. Additionally, this vulnerability exposes sensitive information, allowing attackers to enumerate all WordPress users, along with their IDs and display names, while also potentially accessing role capabilities and nonce values. Such unauthorized access can lead to further exploitation within the site.

Affected Version(s)

EventON Action User 0 <= 2.5.14

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vincent Szopa (bioflavonoid)
.