ZeroHour

CVE-2026-77705

large

WordPress account takeover via broken authorization in Amelia booking plugin < 2.4.10

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

The Booking for Appointments and Events Calendar (Amelia) WordPress plugin before 2.4.10 does not verify that a user editing a customer or employee record is entitled to modify the WordPress account linked to that record (CWE-639, authorization bypass through user-controlled key). An attacker who already holds Amelia's customer or employee management permissions can abuse the plugin's record-editing functionality to set the password and email address of other users' WordPress accounts, including potentially administrators, resulting in full account takeover. Sites running the plugin before 2.4.10 are affected, with practical risk concentrated on installations where those Amelia management permissions are granted to non-admin or otherwise untrusted users. The flaw is rated high severity (CVSS 3.1: 7.2) but requires high privileges to trigger; no public PoC exists and no exploitation in the wild has been reported.

What to do: Upgrade the Amelia plugin to version 2.4.10 or later immediately. Review which user roles hold Amelia's customer/employee management capabilities and strip those permissions from untrusted users, since the flaw is only triggerable by someone with those permissions. Audit user accounts for unexplained password or email changes, reset credentials for any affected or high-value accounts, and check for newly created or elevated administrator accounts.

Affected
wpAmelia Booking for Appointments and Events Calendar – Amelia (WordPress plugin)< 2.4.10
Estimated exposure
large≈100,000 sites (order of magnitude; Amelia is one of the most widely deployed WordPress booking plugins, with tens of thousands to ~100k active installs on… — Estimated from the plugin's WordPress.org active-install count and its popularity in the appointment-booking category, noting that only the subset of sites granting Amelia management permissions to non-admin users is actually exploitable.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.

Ecosystems
WordPress
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.