Junglewise Threat Intelligence

CVE-2026-77705: WordPress Amelia plugin account takeover via authorization bypass

CVE-2026-77705 · Severity: high · CVSS 7.2 · Published 2026-09-12

Technologies: AmeliaBooking Amelia.

Executive brief

The Amelia booking and appointment plugin for WordPress fails to verify that users are authorized to modify customer or employee records, allowing attackers with basic customer or employee management privileges to take over other users' WordPress accounts by changing their passwords and email addresses. This vulnerability puts all WordPress user accounts at risk on sites running the affected plugin, and could lead to full site compromise by attackers gaining administrative access.

Technical details

The vulnerability is an Insecure Direct Object Reference (IDOR) / broken access control flaw in the Amelia WordPress plugin. When a user with customer or employee management permissions attempts to edit a customer or employee record, the plugin fails to verify that they are authorized to modify the associated WordPress account. An attacker holding these management permissions can directly modify the password and email address of any user's WordPress account without additional authorization. This requires the attacker to have legitimate customer or employee management permissions within Amelia but no additional authentication. The vulnerability allows account takeover by changing email and password fields for arbitrary WordPress users. The issue is fixed in version 2.4.10.

Affected products

  • AmeliaBooking Amelia before 2.4.10

Timeline

  • 2026-09-10: disclosed
  • 2026-09-12: patched: Fixed in version 2.4.10
  • 2026-09-12: advisory

References