Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in a popular WordPress plugin used for appointment and event bookings. This flaw could allow unauthorized individuals to gain administrator-level access to WordPress sites, potentially leading to a complete compromise of the website and its data.
- Unauthenticated users could gain administrator access.
- This affects websites using the Amelia booking plugin.
- Confirm relevance and assess potential exposure.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker could exploit this vulnerability by interacting with the booking plugin's customer update endpoint. By manipulating specific parameters, they could create a new user with elevated privileges, effectively gaining administrator access and the ability to overwrite existing administrator passwords.
- Requires no prior authentication.
- Triggered by manipulating customer update endpoint parameters.
- Allows unauthenticated users to become administrators.
Live Threat
Current exploitation, exposure, and threat context
Unauthenticated attackers could potentially gain administrative control of a WordPress site. This is possible when the Booking for Appointments and Events Calendar – Amelia (Premium) plugin is used and an attacker can exploit a flaw in how customer roles are updated. The attacker could first elevate their own role to "manager" and then create a new provider linked to an administrator's user ID, ultimately overwriting the administrator's password.
- WordPress administrator credentials.
- Exploiting a flawed customer update endpoint.
- Complete site takeover by an attacker.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Booking for Appointments and Events Calendar – Amelia (Premium) WordPress plugin's privilege escalation vulnerability necessitates action from platform and security teams. The immediate priority is to inventory all WordPress instances utilizing this plugin, confirm their external reachability and business criticality, identify the accountable application or platform owner, and then develop a remediation plan aligned with identified risks.
- Platform owners should confirm plugin usage.
- Verify plugin exposure and impact.
- Plan coordinated updates or vendor engagement.