The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with customer-level permissions or above to change user passwords and potentially take over administrator accounts. The vulnerability is in the pro plugin, which has the same slug.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ameliabooking
Ameliabooking booking For Appointments And Events Calendar Wordpress Wordpress wordpress |
|
| Vendors & Products |
Ameliabooking
Ameliabooking booking For Appointments And Events Calendar Wordpress Wordpress wordpress |
Thu, 26 Mar 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with customer-level permissions or above to change user passwords and potentially take over administrator accounts. The vulnerability is in the pro plugin, which has the same slug. | |
| Title | Amelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change | |
| Weaknesses | CWE-269 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-03-26T17:51:16.102Z
Reserved: 2026-02-21T06:09:02.642Z
Link: CVE-2026-2931
Updated: 2026-03-26T17:48:32.412Z
Status : Received
Published: 2026-03-26T05:16:39.030
Modified: 2026-03-26T05:16:39.030
Link: CVE-2026-2931
No data.
OpenCVE Enrichment
Updated: 2026-03-26T12:08:39Z