CVE-2026-77705 PUBLISHED

Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover

Assigner: WPScan
Reserved: 21.08.2026 Published: 12.09.2026 Updated: 12.09.2026

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.

Product Status

Vendor Unknown
Product Booking for Appointments and Events Calendar
Versions Default: unaffected
  • affected from 0 to 2.4.10 (excl.)

Credits

  • Karthik Ramakrishnan finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE