Impact
The Booking for Appointments and Events Calendar WordPress plugin before version 2.4.10 does not verify that a user editing a customer or employee record can legitimately modify the WordPress account linked to that record. This flaw allows users with Amelia’s customer or employee management permissions to set another user’s account password and email address, effectively taking over that WordPress account. The vulnerability is categorized as CWE-639, an authorization bypass weakness.
Affected Systems
This vulnerability impacts the Amelia Booking for Appointments and Events Calendar WordPress plugin on all releases before 2.4.10. The vendor is listed as Unknown, but the product is the Amelia plugin for WordPress.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity impact, while the EPSS score current probability of exploitation. The issue is not listed in the CISA KEV catalog. Attackers must already have authenticated access to the WordPress site and possess Amelia customer or employee management roles; with this access, they can addresses without requiring site‑wide takeover.
OpenCVE Enrichment