Description
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with wpamelia-provider role, to view and modify arbitrary customers, including password reset. Takeover of WordPress user accounts, with the roles up to Editor, is also possible if that user had made an Amelia booking. This vulnerability affects only the Premium version of the plugin, where the Employee Panel is present.
Published: 2026-09-17
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Limited Account Takeover via missing authorization to customer endpoints
Action: Patch
AI Analysis

Impact

The Amelia plugin for WordPress includes a missing ownership check on the /users/customers/<id> endpoint. Authenticated users with the wpamelia-provider role can view and modify any customer record, reset passwords, and if a user with a valid booking exists, can assume the role of that user, reaching up to Editor. This results in unauthorized access and potential takeover of WordPress accounts, compromising confidentiality and integrity of user data. The associated weakness is a classic missing privilege check (CWE‑862).

Affected Systems

All installations of melograno's Booking for Appointments and Events Calendar – Amelia Premium plugin up to and including version 2.4.4 are affected. Only the Premium edition, which includes the Employee Panel, contains the vulnerable endpoint. WordPress sites utilizing this plugin should verify the installed version. No other vendors or products are listed.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation as of the data supplied, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated as wpamelia-provider or have a role that can assign that capability; they then exploit the ungated customer endpoint to elevate privileges. Since the flaw only affects a specific plugin version and role, the overall risk is limited, but the impact of a successful takeover can be significant for the target WordPress installation.

Generated by OpenCVE AI on September 19, 2026 at 01:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Amelia plugin to a version newer than 2.4.4, which removes the missing authorization check on the customer endpoint.
  • Restrict the wpamelia-provider role to only essential users, revoking it from any accounts that do not require it.
  • Enforce multi‑factor authentication for users with wpamelia-provider capability to reduce the risk of credential compromise.

Generated by OpenCVE AI on September 19, 2026 at 01:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Ameliabooking
Ameliabooking booking For Appointments And Events Calendar
Wordpress-extensions
Wordpress-extensions booking For Appointments And Events Calendar – Amelia
Vendors & Products Ameliabooking
Ameliabooking booking For Appointments And Events Calendar
Wordpress-extensions
Wordpress-extensions booking For Appointments And Events Calendar – Amelia

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with wpamelia-provider role, to view and modify arbitrary customers, including password reset. Takeover of WordPress user accounts, with the roles up to Editor, is also possible if that user had made an Amelia booking. This vulnerability affects only the Premium version of the plugin, where the Employee Panel is present.
Title Booking for Appointments and Events Calendar – Amelia (Premium) <= 2.4.4 - Authenticated (Custom+) Missing Authorization to Limited Account Takeover
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ameliabooking Booking For Appointments And Events Calendar
Wordpress-extensions Booking For Appointments And Events Calendar – Amelia
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T14:31:41.652Z

Reserved: 2026-07-01T11:37:47.048Z

Link: CVE-2026-14311

cve-icon Vulnrichment

Updated: 2026-09-18T14:29:27.579Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:16:58.627

Modified: 2026-09-18T15:17:05.013

Link: CVE-2026-14311

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T13:22:23Z

Weaknesses