HIGH

CVE-2026-77705

2026-09-12 CVSS v3.1
CVSS
7.2

Description

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.

Weakness (CWE)

CWE-639 Authorization Bypass (IDOR)

EPSS Score

0.32%
Probability of exploitation in next 30 days
24.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE