Impact
The Amelia plugin for WordPress includes a missing ownership check on the /users/customers/<id> endpoint. Authenticated users with the wpamelia-provider role can view and modify any customer record, reset passwords, and if a user with a valid booking exists, can assume the role of that user, reaching up to Editor. This results in unauthorized access and potential takeover of WordPress accounts, compromising confidentiality and integrity of user data. The associated weakness is a classic missing privilege check (CWE‑862).
Affected Systems
All installations of melograno's Booking for Appointments and Events Calendar – Amelia Premium plugin up to and including version 2.4.4 are affected. Only the Premium edition, which includes the Employee Panel, contains the vulnerable endpoint. WordPress sites utilizing this plugin should verify the installed version. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation as of the data supplied, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated as wpamelia-provider or have a role that can assign that capability; they then exploit the ungated customer endpoint to elevate privileges. Since the flaw only affects a specific plugin version and role, the overall risk is limited, but the impact of a successful takeover can be significant for the target WordPress installation.
OpenCVE Enrichment