PT-2026-84598 · WordPress · Amelia

·

CVE-2026-9055

·

Published

2026-09-02

·

Updated

2026-09-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Booking for Appointments and Events Calendar – Amelia (Premium) versions 8.0 through 9.6.2
Description Insufficient validation of the type parameter in the customer update endpoint allows unauthenticated attackers to escalate privileges. By setting the type parameter and setting the externalId parameter to 0, an attacker can trigger the creation of a WordPress user with the wpamelia-manager role. Subsequently, the attacker can elevate their privileges to administrator by creating a provider entity linked to an administrator user ID and overwriting the administrator password.
Recommendations Update Booking for Appointments and Events Calendar – Amelia (Premium) to a version later than 9.6.2.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9055

Affected Products

Amelia