Executive brief
Amelia Pro is a WordPress plugin for booking appointments and managing employees. Due to missing authorization checks, any employee with a login to the employee panel can read and modify personal data of any customer in the system—including names, phone numbers, and notes—without any legitimate business relationship. An attacker with employee credentials can enumerate and alter customer records at will.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) in the employee panel API endpoints. The plugin fails to verify that an authenticated provider (employee) has a booking relationship with the customer whose record is being accessed via sequential ID enumeration. An authenticated employee can call /users/customers/{id} with a valid bearer token to read arbitrary customer records and issue POST requests to modify them. The vulnerability requires valid employee panel credentials and network access to the WordPress installation; no additional user interaction or privilege escalation is needed. Attackers can enumerate sequential customer IDs to discover and modify customer personal data including firstName, lastName, email, phone, and private notes. The issue is fixed in version 9.7.
Affected products
- Elementor Amelia Pro before 9.7
Timeline
- 2026-08-07: disclosed
- 2026-08-07: patched: fixed in version 9.7