CVE-2026-9055

9.8

melograno · Booking for Appointments and Events Calendar – Amelia

The Amelia WordPress plugin contains a critical privilege escalation vulnerability allowing unauthenticated attackers to gain administrative access via improper input validation.

Executive summary

The Booking for Appointments and Events Calendar – Amelia plugin is vulnerable to a critical privilege escalation flaw that allows unauthenticated attackers to gain full administrative control over the WordPress installation.

Vulnerability

The vulnerability exists due to insufficient validation of the type parameter in the customer update endpoint, which permits unauthenticated attackers to manipulate user roles and overwrite administrator credentials.

Business impact

This vulnerability carries a CVSS score of 9.8, indicating a critical risk to the organization. Successful exploitation results in complete system compromise, allowing attackers to exfiltrate sensitive data, modify core configurations, or deploy malicious software, leading to severe reputational damage and potential loss of data integrity.

Remediation

Immediate Action: Update the Amelia plugin to version 9.6.3 or later immediately to resolve the vulnerable code path.

Proactive Monitoring: Review WordPress user access logs for suspicious account creation events or unauthorized role changes, particularly involving the wpamelia-manager role.

Compensating Controls: Deploy a Web Application Firewall (WAF) rule to block unauthorized access to the affected customer update endpoint until the update can be applied.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical nature of this privilege escalation and the ease of exploitation by unauthenticated actors, all administrators using the Amelia plugin must prioritize this update. Failure to patch allows for total site takeover, making immediate remediation the only effective way to secure the environment.

More melograno CVEs

Sources

Originally found and disclosed by d.v4n_s3c, per the CVE Program record.