Impact
The Booking for Appointments and Events Calendar WordPress plugin fails to verify that a user editing a customer or employee record has rights to modify the WordPress account linked to that record. This flaw lets any user with Amelia’s customer or employee management permissions set the password and email address of other WordPress users, effectively hijacking their accounts. The vulnerability reflects CWE-284 (Improper Permission Assignment) and CWE-639 (Credential Assignment), indicating a serious integrity and authentication weakness. The potential consequence is full compromise of those accounts, which can be used to access other site data, post content, or further elevate privileges.
Affected Systems
The vulnerability affects the Amelia Booking for Appointments and Events Calendar WordPress plugin on all versions prior to 2.4.10. The vendor is listed as Unknown, but the product is the Amelia plugin for WordPress.
Risk and Exploitability
EPSS indicates a low probability of exploitation at <1%. The CVSS score of 7.2 denotes a high severity vulnerability. This issue is not listed in the CISA KEV catalog. The flaw allows a user with Amelia customer or employee management permissions, which may be granted to non‑administrator roles, to set the password and email address of other WordPress accounts, effectively hijacking them without needing site‑wide admin access. The impact includes full compromise of targeted accounts, compromising confidentiality, integrity, and availability of the site.
OpenCVE Enrichment