CVE-2026-9055
Received Received - Intake

Privilege Escalation in Amelia WordPress Plugin

Vulnerability report for CVE-2026-9055, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Wordfence

Description

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when the 'externalId' parameter is set to 0. This makes it possible for unauthenticated attackers to escalate their privileges to administrator by first elevating to the manager role, then creating a provider entity linked to an administrator user ID and overwriting that administrator's password.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpamelia amelia From 8.0 (inc) to 9.6.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows unauthenticated attackers to escalate their privileges to administrator level in WordPress sites using the Amelia plugin versions 8.0 to 9.6.2. The issue stems from insufficient validation of the 'type' parameter in a customer update endpoint, enabling attackers to set their role to 'manager' and create a WordPress user with the wpamelia-manager role. By exploiting this, attackers can then create a provider entity linked to an administrator user ID and overwrite that administrator's password, gaining full control.

The vulnerability has a CVSS v3.1 base score of 9.8, indicating critical severity with potential for high impact on confidentiality, integrity, and availability.

Detection Guidance

I don't know

Check if the Amelia plugin version is between 8.0 and 9.6.2. Use WordPress admin panel or run: wp plugin list | grep amelia. If vulnerable, update to version 9.8.1 or later.

Impact Analysis
  • Unauthenticated attackers can gain full administrator access to your WordPress site.
  • Attackers can take complete control of your site, including modifying content, stealing data, or installing malicious software.
  • Sensitive customer or business data stored in the Amelia plugin could be accessed or exfiltrated.
  • Your site could be used to host malware or launch attacks on other systems.
Compliance Impact

This vulnerability could lead to unauthorized access and exposure of sensitive personal data, violating GDPR's data protection requirements and potentially HIPAA's safeguards for protected health information. Organizations may face regulatory fines, legal liabilities, and reputational damage due to non-compliance resulting from this breach.

Mitigation Strategies

Update the Amelia plugin to version 9.8.1 or later immediately. Disable the plugin temporarily if an update is not immediately possible. Review user roles for unauthorized manager accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9055. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart