Impact
The vulnerability is a missing authorization flaw that allows an attacker to exploit incorrectly configured access control security levels in the WordPress Amelia booking plugin. This flaw enables unauthorized users to access or manipulate functions that should be restricted to privileged users. The primary impact is unauthorized access or privilege escalation within the plugin’s administrative interface.
Affected Systems
The affected product is the WordPress Amelia booking plugin (ameliabooking) from TMS Amelia. Versions from the earliest release up to and including 2.4.10 are impacted. Any WordPress installation that has this plugin deployed without updating to 2.4.11 or later is susceptible.
Risk and Exploitability
With a CVSS score of 7.5 the issue is classified as high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an external attacker sending crafted HTTP requests to the plugin’s administrative endpoints, taking advantage of the missing access control checks. This inference is based on the description of a missing authorization flaw, though the precise exploitation method is not detailed in the CVE record.
OpenCVE Enrichment