EventON Action User
EventON Action User is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 7.3.
eventon-action-userCVE-2026-10033: EventON Action User AJAX authorization bypass permits privilege escalation
EventON Action User through 2.5.14 exposes the evoau_save_capability AJAX action without an effective authentication or authorization check. An unauthenticated request can reach update_role_caps() and grant EventON management capabilities plus upload_files to a selected non-administrator WordPress role or user. The administrator role has an early-return guard, but other roles and individual users remain targetable; related exposed handlers can also enumerate user IDs and display names, disclose capability state and nonce values, and alter event-to-user term assignments.
| Safe version |
|
||
|---|---|---|---|
| Jul 24, 2026 |
CVE-2026-10033
EventON Action User AJAX authorization bypass permits privilege escalation
EventON Action User through 2.5.14 exposes the evoau_save_capability AJAX action without an effective authentication or authorization check. An unauthenticated request can reach update_role_caps() and grant EventON management capabilities plus upload_files to a selected non-administrator WordPress role or user. The administrator role has an early-return guard, but other roles and individual users remain targetable; related exposed handlers can also enumerate user IDs and display names, disclose capability state and nonce values, and alter event-to-user term assignments.
|
2.5.15 |
CVE7.3
NVDPending
|