PT-2026-30799 · WordPress · Amelia
Published
2026-04-07
·
Updated
2026-04-07
·
CVE-2026-5465
CVSS v3.1
8.8
High
| AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Amelia plugin for WordPress versions up to and including 2.1.3
Description
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is susceptible to Insecure Direct Object Reference. The
UpdateProviderCommandHandler does not properly validate modifications to the externalId field when a Provider (Employee) user updates their profile. The externalId directly corresponds to a WordPress user ID and is used in the wp set password() and wp update user() functions without authorization checks. This allows authenticated attackers with Provider-level (Employee) access or higher to potentially compromise any WordPress account, including Administrator accounts, by manipulating the externalId value during their own provider profile update.Recommendations
Update the Amelia plugin to a version later than 2.1.3.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amelia