CRITICAL 9.8 CVE-2026-9055 Published 2 Sept 2026

WordPress Amelia Plugin Privilege Escalation

Worried this affects one of your servers?

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2.

This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, allowing customers to set their role to 'manager'.

Unauthenticated attackers can escalate their privileges to administrator by first elevating to the manager role, then creating a provider entity linked to an administrator user ID and overwriting that administrator's password.

Reference: CVE-2026-9055 on NVD

← Back to Security News