Impact
The Booking for Appointments and Events Calendar plugin, which powers the Amelia calendar in WordPress, fails to verify that a user possesses the proper capability before changing an appointment’s status. Because of this oversight, any customer who has an appointment can arbitrarily modify the status, including approving their own pending bookings and overriding the status set by other customers on shared appointments. This flaw effectively allows users to bypass administrative approval workflows and can lead to unauthorized transaction processing or service access.
Affected Systems
The vulnerability applies to Amelia plugin versions 1.2.32 through 2.4.8, the last release before 2.4.9, which is the first version that includes the missing capability checks. It affects any WordPress tenant that utilizes the Amelia booking module, regardless of the theme or other plugins, since the flaw lies in Amelia’s core code.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is through the normal WordPress user interface or an exposed REST endpoint, giving attackers a low barrier to life. The flaw has no CVSS score provided in the public record and the EPSS score is not available, but the absence of an access control check renders the vulnerability highly exploitable in any environment where the site is publicly reachable and users can submit status changes.
OpenCVE Enrichment