
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-10033 is an authorization bypass vulnerability in the EventON Action User plugin for WordPress, affecting all versions up to and including 2.5.14. The flaw allows unauthenticated remote attackers to escalate privileges of non-administrator users and roles, enumerate WordPress users, and tamper with event-to-user assignments. It was published on July 24, 2026, with a CVSS v3.1 base score of 7.3 (High) (GitHub Advisory, Wordfence).
The root cause is a missing authorization check (CWE-862) in the plugin's admin AJAX handler, specifically within class-admin-ajax.php around line 243, where the plugin fails to verify that the requesting user is authorized before performing privileged actions. An unauthenticated attacker can send crafted network requests to WordPress AJAX endpoints exposed by the plugin to invoke update_role_caps() and grant EventON management capabilities and the upload_files capability to any non-administrator role or individual user. The administrator role is partially protected by an early-return guard in update_role_caps(), limiting direct administrator-level privilege escalation, but all other roles and users remain fully exposed. The same unauthenticated endpoint also leaks user IDs, display names, role/capability state, and nonce values (GitHub Advisory, Wordfence).
Successful exploitation allows unauthenticated attackers to escalate the privileges of any non-administrator WordPress user or role by granting them EventON management capabilities and the upload_files capability, which could enable malicious file uploads and further site compromise. Additionally, attackers can enumerate all WordPress users along with their IDs, display names, role assignments, capability states, and nonce values — facilitating targeted follow-on attacks such as credential stuffing or session hijacking. Attackers can also tamper with event-to-user term assignments, disrupting site functionality and data integrity (GitHub Advisory, Wordfence).
/wp-content/plugins/eventon-action-user/./wp-admin/admin-ajax.php) with the appropriate action parameter exposed by the plugin to retrieve a list of all WordPress users, their IDs, display names, roles, capabilities, and nonce values.class-admin-ajax.php around line 243) with parameters specifying the target user/role and the desired capabilities (eventon management capabilities and upload_files).upload_files capability, achieving remote code execution or persistent access to the WordPress site (GitHub Advisory, Wordfence)./wp-admin/admin-ajax.php with action parameters associated with the EventON Action User plugin; repeated requests from a single IP enumerating user data.admin-ajax.php; server logs indicating unexpected capability or role modification events.wp_usermeta) reflecting newly granted capabilities (e.g., upload_files, EventON management caps) for non-administrator accounts; unexpected modifications to wp_term_relationships for event-to-user assignments.www-data) following file upload activity.Update the EventON Action User plugin to a version newer than 2.5.14 as soon as a patched release becomes available. Site administrators should immediately audit user roles and capabilities in the WordPress dashboard to identify any unauthorized privilege grants to non-administrator accounts. As a temporary workaround where patching is not immediately possible, restrict access to wp-admin/admin-ajax.php via network-level controls (e.g., firewall rules, WAF rules) to limit unauthenticated exposure to the plugin's administrative functions (GitHub Advisory, Wordfence).
The vulnerability was discovered and reported by Wordfence, which published the initial threat intelligence entry on July 24, 2026. No significant broader media coverage, researcher commentary, or notable social media discussion has been identified at this time (Wordfence).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"