Authorization Bypass Vulnerability in EventON Action User Plugin for WordPress
CVE-2026-10033
7.3HIGH
What is CVE-2026-10033?
The EventON Action User plugin for WordPress is affected by a significant vulnerability that allows unauthorized users to bypass normal access controls. This flaw enables an unauthenticated attacker to grant themselves management capabilities within the plugin, including the ability to upload files, thereby escalating their privileges without proper authorization checks. Additionally, this vulnerability exposes sensitive information, allowing attackers to enumerate all WordPress users, along with their IDs and display names, while also potentially accessing role capabilities and nonce values. Such unauthorized access can lead to further exploitation within the site.
Affected Version(s)
EventON Action User 0 <= 2.5.14