CVE-2026-77705
largeWordPress account takeover via broken authorization in Amelia booking plugin < 2.4.10
The Booking for Appointments and Events Calendar (Amelia) WordPress plugin before 2.4.10 does not verify that a user editing a customer or employee record is entitled to modify the WordPress account linked to that record (CWE-639, authorization bypass through user-controlled key). An attacker who already holds Amelia's customer or employee management permissions can abuse the plugin's record-editing functionality to set the password and email address of other users' WordPress accounts, including potentially administrators, resulting in full account takeover. Sites running the plugin before 2.4.10 are affected, with practical risk concentrated on installations where those Amelia management permissions are granted to non-admin or otherwise untrusted users. The flaw is rated high severity (CVSS 3.1: 7.2) but requires high privileges to trigger; no public PoC exists and no exploitation in the wild has been reported.
What to do: Upgrade the Amelia plugin to version 2.4.10 or later immediately. Review which user roles hold Amelia's customer/employee management capabilities and strip those permissions from untrusted users, since the flaw is only triggerable by someone with those permissions. Audit user accounts for unexplained password or email changes, reset credentials for any affected or high-value accounts, and check for newly created or elevated administrator accounts.
| wpAmelia Booking for Appointments and Events Calendar – Amelia (WordPress plugin) | < 2.4.10 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
- Ecosystems
- WordPress
- Weakness
- CWE-639
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.