CVE-2026-77705: Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
Affected Software
Event History
Frequently Asked Questions
Which users could exploit this issue?
Users who hold Amelia customer or employee management permissions could exploit it. The issue arises because those permissions do not ensure the user is entitled to modify the linked WordPress account.
What can an attacker change to take over an account?
An authorized Amelia customer or employee manager can set the password and email address of another user's linked WordPress account, enabling account takeover.
Which versions are affected?
Amelia versions before 2.4.10 are affected.