Description
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
Published: 2026-09-12
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Account Takeover
Action: Immediate Patch
AI Analysis

Impact

The Booking for Appointments and Events Calendar WordPress plugin before version 2.4.10 does not verify that a user editing a customer or employee record can legitimately modify the WordPress account linked to that record. This flaw allows users with Amelia’s customer or employee management permissions to set another user’s account password and email address, effectively taking over that WordPress account. The vulnerability is categorized as CWE-639, an authorization bypass weakness.

Affected Systems

This vulnerability impacts the Amelia Booking for Appointments and Events Calendar WordPress plugin on all releases before 2.4.10. The vendor is listed as Unknown, but the product is the Amelia plugin for WordPress.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity impact, while the EPSS score current probability of exploitation. The issue is not listed in the CISA KEV catalog. Attackers must already have authenticated access to the WordPress site and possess Amelia customer or employee management roles; with this access, they can addresses without requiring site‑wide takeover.

Generated by OpenCVE AI on September 15, 2026 at 18:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Amelia plugin to version 2.4.10 or later to apply the vendor’s fix.
  • Restrict Amelia customer or employee management roles to trusted users only, removing unnecessary privileges.
  • Audit user accounts for unauthorized changes and enforce a strong password policy for all site users.

Generated by OpenCVE AI on September 15, 2026 at 18:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
Title Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:35:37.592Z

Reserved: 2026-08-21T08:04:51.534Z

Link: CVE-2026-77705

cve-icon Vulnrichment

Updated: 2026-09-12T15:25:10.175Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:24.967

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-77705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:00:15Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key