Description
Missing Authorization vulnerability in TMS Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through 2.4.10.
Published: 2026-10-09
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized Access / Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows an attacker to exploit incorrectly configured access control security levels in the WordPress Amelia booking plugin. This flaw enables unauthorized users to access or manipulate functions that should be restricted to privileged users. The primary impact is unauthorized access or privilege escalation within the plugin’s administrative interface.

Affected Systems

The affected product is the WordPress Amelia booking plugin (ameliabooking) from TMS Amelia. Versions from the earliest release up to and including 2.4.10 are impacted. Any WordPress installation that has this plugin deployed without updating to 2.4.11 or later is susceptible.

Risk and Exploitability

With a CVSS score of 7.5 the issue is classified as high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an external attacker sending crafted HTTP requests to the plugin’s administrative endpoints, taking advantage of the missing access control checks. This inference is based on the description of a missing authorization flaw, though the precise exploitation method is not detailed in the CVE record.

Generated by OpenCVE AI on October 9, 2026 at 12:28 UTC.

Remediation

Vendor Solution

Update the WordPress Amelia plugin to the latest available version (at least 2.4.11).


OpenCVE Recommended Actions

  • Install or upgrade the WordPress Amelia plugin to version 2.4.11 or later to apply the vendor’s patch.
  • Reconfigure the plugin’s access controls so that only users with the appropriate roles can access administrative functionalities.
  • If an upgrade cannot be performed immediately, restrict access to the plugin’s administrative URLs using web‑server configuration or a WordPress security plugin until a patch is applied.

Generated by OpenCVE AI on October 9, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in TMS Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through 2.4.10.
Title WordPress Amelia plugin <= 2.4.10 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:17.179Z

Reserved: 2026-09-23T10:00:09.038Z

Link: CVE-2026-96461

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T10:16:45.000

Modified: 2026-10-09T10:16:45.000

Link: CVE-2026-96461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T12:30:05Z

Weaknesses