Back

HIGH

Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover

Published Sep 12, 2026

Description

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner WPScan
Published Sep 12, 2026
Updated Sep 12, 2026
Reserved Aug 21, 2026

CISA Vulnrichment

Updated Sep 12, 2026

NVD

Status Deferred
Modified Sep 14, 2026

Red Hat

No data

ENISA EUVD

Assigner WPScan
Published Sep 12, 2026
Updated Sep 12, 2026

GitHub

No data