Junglewise Threat Intelligence

CVE-2026-40795: TMS Amelia broken access control in WordPress plugin

CVE-2026-40795 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Technologies: TMS-Outsource Amelia. Vendors: TMS-Outsource, TMS.

Executive brief

The Amelia plugin for WordPress, which is used for managing automated bookings and appointments, contains a security flaw that allows users with low-level 'Subscriber' accounts to perform actions they should not be authorized to do. This could allow an attacker to modify booking data or settings, potentially disrupting business operations and appointment scheduling. Organizations using this plugin should update to version 2.2.1 immediately to prevent unauthorized changes to their booking system.

Technical details

A broken access control vulnerability exists in the TMS Amelia plugin for WordPress (versions <= 2.2) due to missing authorization checks (CWE-862). An attacker authenticated with a low-privilege 'Subscriber' role can exploit this flaw over the network without user interaction. The vulnerability allows the attacker to execute functions or modify data that should be restricted to higher-privileged users, specifically impacting the integrity of the system. The issue is resolved in version 2.2.1.

Affected products

  • TMS Amelia <= 2.2

Timeline

  • 2026-03-29: other: Reported by Niv Kochan
  • 2026-04-28: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References

Related threats