Impact
The vulnerability allows an unauthenticated attacker to send a crafted request to the customer update endpoint of the Amelia plugin, setting the customer role to manager. By providing an externalId of 0, the system creates a WordPress user with the wpamelia‑manager role, and the attacker can then associate a provider entity to an existing administrator account and overwrite that administrator's password, effectively gaining full administrative control.
Affected Systems
The affected product is the melograno Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress. Versions from 8.0 up to and including 9.6.2 are impacted. Any WordPress site running these plugin versions is at risk.
Risk and Exploitability
With a CVSS score of 9.8 the risk level is Critical. The exploit is likely achieved via a simple unauthenticated HTTP request to the plugin’s update endpoint, so the attack vector is network‑based. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog; still, the lack of authentication requirements and the high severity make immediate remediation essential.
OpenCVE Enrichment