PT-2026-30799 · WordPress · Amelia

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-5465

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Amelia plugin for WordPress versions up to and including 2.1.3
Description The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is susceptible to Insecure Direct Object Reference. The UpdateProviderCommandHandler does not properly validate modifications to the externalId field when a Provider (Employee) user updates their profile. The externalId directly corresponds to a WordPress user ID and is used in the wp set password() and wp update user() functions without authorization checks. This allows authenticated attackers with Provider-level (Employee) access or higher to potentially compromise any WordPress account, including Administrator accounts, by manipulating the externalId value during their own provider profile update.
Recommendations Update the Amelia plugin to a version later than 2.1.3.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-5465

Affected Products

Amelia