Executive brief
The EventON Action User plugin for WordPress, which allows users to manage events, contains a security flaw that permits unauthorized individuals to change user permissions. An attacker could use this to grant themselves or others the ability to manage events and upload files, potentially leading to unauthorized site modifications. Additionally, the flaw allows attackers to view a list of all registered users and their internal account details.
Technical details
The EventON Action User plugin for WordPress suffers from a missing authorization check (CWE-862) in its AJAX handlers, specifically within the update_role_caps() function. This vulnerability allows unauthenticated remote attackers to modify WordPress role capabilities, granting 'upload_files' and EventON management permissions to any role or user except the protected administrator role. Beyond privilege escalation, the flaw enables unauthenticated attackers to enumerate all WordPress users (IDs and display names), disclose internal role/capability states, and leak security nonces. The issue is present in all versions up to and including 2.5.14.
Affected products
- EventON EventON Action User <= 2.5.14
Timeline
- 2026-07-24: disclosed: Initial publication of the vulnerability details.
- 2026-07-24: advisory: Wordfence published the vulnerability advisory.