Junglewise Threat Intelligence

CVE-2026-48889: TMS Amelia privilege escalation in WordPress plugin

CVE-2026-48889 · Severity: high · CVSS 8.8 · Published 2026-06-15

Technologies: TMS-Outsource Amelia. Vendors: TMS-Outsource, TMS.

Executive brief

Amelia is a popular WordPress plugin used for managing appointments and events. A security flaw allows users with low-level 'Subscriber' accounts to gain unauthorized higher-level permissions. This could allow an attacker to take full control of the website, potentially leading to data theft or a complete site shutdown.

Technical details

The Amelia plugin for WordPress (versions 2.3 and below) contains a privilege escalation vulnerability classified as CWE-266 (Incorrect Privilege Assignment). The flaw allows an authenticated attacker with 'Subscriber' level permissions to escalate their privileges via the network without user interaction. By exploiting this root cause in the plugin's permission handling, an attacker can gain higher-level access, potentially leading to full site compromise. The vulnerability is addressed in version 2.4.

Affected products

  • TMS Amelia <= 2.3

Timeline

  • 2026-05-08: other: Reported by researcher dodoh4t
  • 2026-06-02: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References

Related threats