WordPress security changelog
HIGH CVE-2026-77705 Received

Amelia record editing can take over linked WordPress accounts

Booking for Appointments and Events Calendar before 2.4.10 does not verify that a user editing a customer or employee record may modify the WordPress account linked to it. A user with Amelia customer or employee management permission can change another user's email address and password and take over that account. The authoritative export does not name the handler, record identifier, or submitted fields.

CVE / CNA score 7.2 CVSS 3.1 · 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD score Pending NVD has not published its own CVSS assessment.
Component
Booking for Appointments and Events Calendar
Plugin slug
booking-for-appointments-and-events-calendar
Affected
< 2.4.10
Safe version
2.4.10
Published
Sep 12, 2026
Weakness
CWE-639 — Authorization Bypass Through User-Controlled Key

This CVE was published Sep 12, 2026 and is one of 6 known issues for this plugin.

Update, patch or deactivate.

Update the plugin to 2.4.10 or later. The authoritative affected range ends before 2.4.10. The application-level fix must authorize both the Amelia record and linked WordPress user, and prevent lower-privilege managers from changing credentials or accounts outside their scope.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Primary and upstream sources