Junglewise Threat Intelligence

CVE-2026-77704: Amelia Booking improper authorization in appointment status update

CVE-2026-77704 · Severity: low · CVSS 2.7 · Published 2026-08-29

Executive brief

Amelia is a popular WordPress plugin for appointment and event booking. The plugin fails to verify that a customer has permission to change appointment statuses, allowing them to self-approve their own pending bookings without administrator review, cancel other customers' bookings on shared time slots, and modify appointment records. This undermines the approval workflow and can disrupt service delivery and customer trust.

Technical details

The vulnerability is an improper authorization (CWE-863) flaw in the appointment status update endpoint. The plugin accepts AJAX requests to change appointment status via /wp-admin/admin-ajax.php?action=wpamelia_api&call=/appointments/status/ but does not verify that the requesting user holds the required capability to perform that action. An authenticated WordPress user with the Amelia Customer role can forge a POST request with a valid nonce to transition any appointment they are associated with to any status (pending, approved, cancelled, rejected, no-show). In certain configurations (shared time slots, default pending status), this also allows a customer to overwrite another customer's booking status. The issue requires authentication and a valid nonce (obtained from a page a customer can access), but no administrative action. Fixed in version 2.4.9.

Affected products

  • Amelia Booking for Appointments and Events Calendar 1.2.32–2.4.8

Timeline

  • 2026-08-27: disclosed
  • 2026-08-29: patched: Fixed in version 2.4.9

References