← Terug naar overzicht

The Amelia Premium plugin for WordPress (versions 8.0 to 9.6.2) contains a critical privilege escalation vulnerability tracked as CVE-2026-9055. The flaw stems from insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint. An unauthenticated attacker can exploit this by first elevating their role to 'manager' via the customer update endpoint, then creating a provider entity linked to an administrator user ID to overwrite that administrator's password. This two-stage attack chain allows full administrator-level compromise of the WordPress installation. The vulnerability is triggered when the 'externalId' parameter is set to 0, causing creation of a WordPress user with the wpamelia-manager role. No authentication is required to initiate the attack, making this a significant risk for any site running the affected plugin versions.

Affected products

  • Amelia Premium WordPress Plugin (versions 8.0 - 9.6.2)

Related CVE's

  • CVE-2026-9055

Categories

  • Identity & Access
  • Web Technologies
  • Zero-Day Vulnerabilities