CVE-2026-24963: WordPress Amelia plugin <= 1.2.38 - Privilege Escalation vulnerability
Published Mar 5, 2026
·Updated
Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issue affects Amelia: from n/a through <= 1.2.38.
Affected Software
2 affected components
Amelia Amelia<=1.2.38
wordpress/amelia<=1.2.38
Event History
Mar 5, 2026
CVE Published
via MITRE·05:53 AM
Data Sourced
via MITRE·05:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-24963?
CVE-2026-24963 is classified as a privilege escalation vulnerability affecting the Amelia plugin for WordPress.
2
How do I fix CVE-2026-24963?
To fix CVE-2026-24963, update the Amelia plugin to a version higher than 1.2.38.
3
What versions of the Amelia plugin are affected by CVE-2026-24963?
CVE-2026-24963 affects all versions of the Amelia plugin up to and including 1.2.38.
4
What impact does CVE-2026-24963 have on WordPress sites?
CVE-2026-24963 allows unauthorized users to escalate their privileges within WordPress sites using the Amelia plugin.
5
Is there a known exploit for CVE-2026-24963?
As of now, there are no public exploits reported for CVE-2026-24963, but it is crucial to apply the necessary updates to mitigate potential risks.