What is CVE-2026-10033?
The EventON Action User plugin for WordPress (up to version 2.5.14) has an authorization bypass vulnerability. This allows unauthenticated attackers to grant themselves EventON manager privileges. Administrators should update the plugin immediately.
Azərbaycanca: WordPress-in EventON Action User plaginində (versiyalar <= 2.5.14) avtorizasiya zəifliyi aşkarlanıb. Bu, autentifikasiya olunmamış hücumçulara EventON meneceri səlahiyyətlərini əldə etməyə imkan verir. Administrasiya plaginləri dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
What versions of the EventON Action User plugin are affected by CVE-2026-10033?
This vulnerability affects EventON Action User plugin versions up to and including 2.5.14.
What can an unauthenticated attacker gain by exploiting CVE-2026-10033?
An unauthenticated attacker can grant themselves EventON manager privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.