← WordPress Vulnerabilities
WordPress security by component

EventON Action User

EventON Action User is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 7.3.

Plugin slug: eventon-action-user

CVE-2026-10033: EventON Action User AJAX authorization bypass permits privilege escalation

EventON Action User through 2.5.14 exposes the evoau_save_capability AJAX action without an effective authentication or authorization check. An unauthenticated request can reach update_role_caps() and grant EventON management capabilities plus upload_files to a selected non-administrator WordPress role or user. The administrator role has an early-return guard, but other roles and individual users remain targetable; related exposed handlers can also enumerate user IDs and display names, disclose capability state and nonce values, and alter event-to-user term assignments.

PublishedJul 24, 2026
Known safe version2.5.15
Safe version
Jul 24, 2026 CVE-2026-10033
EventON Action User AJAX authorization bypass permits privilege escalation
EventON Action User through 2.5.14 exposes the evoau_save_capability AJAX action without an effective authentication or authorization check. An unauthenticated request can reach update_role_caps() and grant EventON management capabilities plus upload_files to a selected non-administrator WordPress role or user. The administrator role has an early-return guard, but other roles and individual users remain targetable; related exposed handlers can also enumerate user IDs and display names, disclose capability state and nonce values, and alter event-to-user term assignments.
2.5.15
CVE7.3
NVDPending