Impact
The Booking for Appointments and Events Calendar WordPress plugin accepts user imports without restricting which fields can be written. A user granted the Amelia Manager role can supply arbitrary column names in the import request, causing the plugin to write any desired value into any stored user record. This allows modification of sensitive attributes such as user roles, status, or other personal data, thereby compromising data integrity and potentially enabling full control over a WordPress site. The weakness is a classic example of unchecked mass assignment—a failure in access control that can be exploited for privilege escalation. The flaw also aligns with CWE‑287, highlighting risks related to insecure authentication mechanisms.
Affected Systems
WordPress installations running the Amelia Booking for Appointments and Events Calendar plugin version 2.4.3 or earlier. Only sites with the plugin installed are affected; no other vendor or product versions are referenced.
Risk and Exploitability
The EPSS score of <1% indicates a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread, active exploitation. However, the attack requires a user with the Amelia Manager role to trigger the import; if such a role exists, the attacker can immediately alter arbitrary user records. The lack of a publicly disclosed patch or workaround in the advisory means the primary risk is for sites still on older versions, where the flaw remains unmitigated. The CVSS score of 2.7 reflects low severity, suggesting limited impact if mitigated.
OpenCVE Enrichment