A vulnerability was found in EventON Action User Plugin up to 2.5.14 on WordPress and classified as critical. This affects the function
update_role_caps. The manipulation results in authorization bypass.
This vulnerability is known as CVE-2026-10033. It is possible to launch the attack remotely. No exploit is available.