CVE-2026-9055
9.8melograno · Booking for Appointments and Events Calendar – Amelia
The Amelia WordPress plugin contains a critical privilege escalation vulnerability allowing unauthenticated attackers to gain administrative access via improper input validation.
Executive summary
The Booking for Appointments and Events Calendar – Amelia plugin is vulnerable to a critical privilege escalation flaw that allows unauthenticated attackers to gain full administrative control over the WordPress installation.
Vulnerability
The vulnerability exists due to insufficient validation of the type parameter in the customer update endpoint, which permits unauthenticated attackers to manipulate user roles and overwrite administrator credentials.
Business impact
This vulnerability carries a CVSS score of 9.8, indicating a critical risk to the organization. Successful exploitation results in complete system compromise, allowing attackers to exfiltrate sensitive data, modify core configurations, or deploy malicious software, leading to severe reputational damage and potential loss of data integrity.
Remediation
Immediate Action: Update the Amelia plugin to version 9.6.3 or later immediately to resolve the vulnerable code path.
Proactive Monitoring: Review WordPress user access logs for suspicious account creation events or unauthorized role changes, particularly involving the wpamelia-manager role.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule to block unauthorized access to the affected customer update endpoint until the update can be applied.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical nature of this privilege escalation and the ease of exploitation by unauthenticated actors, all administrators using the Amelia plugin must prioritize this update. Failure to patch allows for total site takeover, making immediate remediation the only effective way to secure the environment.
More melograno CVEs
Sources
Originally found and disclosed by d.v4n_s3c, per the CVE Program record.