← Back to overview

The Amelia Premium plugin for WordPress contains a critical privilege escalation vulnerability affecting versions 8.0 through 9.6.2. The flaw stems from insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint. An unauthenticated attacker can exploit this by first elevating their role to 'manager' by manipulating the 'type' parameter, then setting the 'externalId' parameter to 0 to trigger creation of a WordPress user with the wpamelia-manager role. Subsequently, the attacker can create a provider entity linked to an administrator user ID and overwrite that administrator's password. This multi-step attack chain ultimately allows full administrator-level access to the WordPress site. The vulnerability poses a significant risk to any WordPress site running the affected versions of the Amelia Premium booking plugin.

Affected products

  • Booking for Appointments and Events Calendar – Amelia Premium plugin for WordPress (versions 8.0 - 9.6.2)

Related CVE's

  • CVE-2026-9055

Categories

  • Identity & Access
  • Web Technologies
  • Zero-Day Vulnerabilities