Junglewise Threat Intelligence

CVE-2026-9055: WordPress Amelia Premium privilege escalation in customer update endpoint

CVE-2026-9055 · Severity: critical · CVSS 9.8 · Published 2026-09-02

Vendors: TMS.

Executive brief

The Amelia Premium WordPress plugin for booking appointments and events contains a privilege escalation vulnerability that allows unauthenticated attackers to gain full administrator access to a WordPress site. By manipulating API parameters, an attacker can first elevate their own account to manager status, then overwrite administrator credentials, resulting in complete site takeover and potential exposure of all customer booking data and site functionality.

Technical details

The vulnerability is a privilege escalation resulting from insufficient validation of the 'type' parameter in the customer update API endpoint. Unauthenticated attackers can exploit this by setting their role to 'manager' with the 'externalId' parameter set to 0, triggering creation of a WordPress user with the wpamelia-manager role. From this elevated manager position, an attacker can then create a provider entity linked to an administrator user ID and overwrite that administrator's password, achieving full administrator privileges. The vulnerability affects versions 8.0 through 9.6.2 and requires no authentication or user interaction to exploit.

Affected products

  • TMS Amelia Premium 8.0 through 9.6.2

Timeline

  • 2026-09-02: disclosed

References