CVE-2026-2931 PUBLISHED

Amelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change

Assigner: Wordfence
Reserved: 21.02.2026 Published: 26.03.2026 Updated: 26.03.2026

The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with customer-level permissions or above to change user passwords and potentially take over administrator accounts. The vulnerability is in the pro plugin, which has the same slug.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor ameliabooking
Product Booking for Appointments and Events Calendar – Amelia
Versions Default: unaffected
  • affected from * to 9.1.2 (incl.)

Credits

  • Hunter Jensen finder

References

Problem Types

  • CWE-269 Improper Privilege Management CWE