Description
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
Published: 2026-09-12
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Account Takeover
Action: Immediate Patch
AI Analysis

Impact

The Booking for Appointments and Events Calendar WordPress plugin fails to verify that a user editing a customer or employee record has rights to modify the WordPress account linked to that record. This flaw lets any user with Amelia’s customer or employee management permissions set the password and email address of other WordPress users, effectively hijacking their accounts. The vulnerability reflects CWE-284 (Improper Permission Assignment) and CWE-639 (Credential Assignment), indicating a serious integrity and authentication weakness. The potential consequence is full compromise of those accounts, which can be used to access other site data, post content, or further elevate privileges.

Affected Systems

The vulnerability affects the Amelia Booking for Appointments and Events Calendar WordPress plugin on all versions prior to 2.4.10. The vendor is listed as Unknown, but the product is the Amelia plugin for WordPress.

Risk and Exploitability

EPSS indicates a low probability of exploitation at <1%. The CVSS score of 7.2 denotes a high severity vulnerability. This issue is not listed in the CISA KEV catalog. The flaw allows a user with Amelia customer or employee management permissions, which may be granted to non‑administrator roles, to set the password and email address of other WordPress accounts, effectively hijacking them without needing site‑wide admin access. The impact includes full compromise of targeted accounts, compromising confidentiality, integrity, and availability of the site.

Generated by OpenCVE AI on September 12, 2026 at 18:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Amelia plugin to version 2.4.10 or later to apply the vendor’s fix.
  • Review and restrict Amelia customer or employee management roles so only trusted users can modify WordPress accounts linked to customers or employees.
  • Audit all affected user accounts for unauthorized changes and enforce a strong password policy for all accounts.

Generated by OpenCVE AI on September 12, 2026 at 18:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
Title Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:35:37.592Z

Reserved: 2026-08-21T08:04:51.534Z

Link: CVE-2026-77705

cve-icon Vulnrichment

Updated: 2026-09-12T15:25:10.175Z

cve-icon NVD

Status : Received

Published: 2026-09-12T06:16:24.967

Modified: 2026-09-12T16:16:38.943

Link: CVE-2026-77705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-12T18:30:15Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key