CVE-2026-2931 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: March 26, 2026
Amelia Booking WordPress plugin - Broken Access Control
Published: March 26, 2026Updated: March 26, 2026Remote Exploitable
Overview
Amelia Booking WordPress plugin <= 9.1.2 contains an insecure direct object reference caused by user-controlled access to objects in the pro plugin, letting authenticated users with customer-level permissions change passwords and take over admin accounts.
Severity & Score
Severity: High
CVSS Score: 8.8
Impact
Authenticated users can change passwords and potentially take over administrator accounts, leading to full system compromise.
Mitigation
Update to the latest version beyond 9.1.2.
References
- https://codecanyon.net/item/amelia-enterpriselevel-appointment-booking-wordpress-plugin/22067497
- https://plugins.trac.wordpress.org/browser/ameliabooking/tags/2.1/src/Application/Commands/User/Customer/UpdateCustomerCommandHandler.php#L173
- https://plugins.trac.wordpress.org/browser/ameliabooking/tags/2.1/src/Application/Controller/User/Customer/UpdateCustomerController.php#L30
- https://www.wordfence.com/threat-intel/vulnerabilities/id/9dbaafbb-ab7b-41d8-a8f7-178b9d42b4c5?source=cve
Related Resources
Details
- CVE ID
- CVE-2026-2931
- Severity
- High
- CVSS Score
- 8.8
- Type
- broken_access_control
- Status
- new
CWE
- CWE-269
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H