CVE-2026-9055 Details
Description
The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when the 'externalId' parameter is set to 0. This makes it possible for unauthenticated attackers to escalate their privileges to administrator by first elevating to the manager role, then creating a provider entity linked to an administrator user ID and overwriting that administrator's password.
A privilege escalation vulnerability has been identified in the Booking for Appointments and Events Calendar - Amelia (Premium) plugin for WordPress, affecting versions 8.0 to 9.6.2. The vulnerability arises from inadequate validation of the 'type' parameter in the customer update endpoint, allowing customers to change their role to 'manager'. When the 'externalId' parameter is set to 0, this action triggers the creation of a WordPress user with the wpamelia-manager role. This exploitation enables unauthenticated attackers to first elevate their privileges to manager, and then to administrator by creating a provider entity linked to an administrator user ID and overwriting that administrator's password.
Users are advised to update the Amelia plugin to version 9.6.3 or a newer patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 2, 2026CISA-ADP
Assessed Sep 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Amelia | >= 8.0, <= 9.6.2 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 2, 2026 | CVE Modified | CISA-ADP |
| Sep 2, 2026 | New CVE Received | [email protected] |
Volerion