PT-2026-28198 · WordPress · Amelia Booking Plugin
Hunter Jensen
·
Publicado
2026-03-26
·
Atualizado
2026-03-27
·
CVE-2026-2931
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Amelia Booking plugin for WordPress versions up to 9.1.2
Description
The Amelia Booking plugin for WordPress is susceptible to Insecure Direct Object References. The plugin allows user-controlled access to objects, potentially enabling a user to bypass authorization and access system resources. Authenticated attackers with customer-level permissions or above may be able to change user passwords and potentially gain control of administrator accounts. The issue exists in the pro plugin.
Recommendations
Update the Amelia Booking plugin to a version later than 9.1.2.
Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Amelia Booking Plugin