External risk intelligence

Amelia WordPress Plugin Privilege Escalation Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-9055

The vulnerability affects a WordPress plugin designed to provide booking and calendar functionality, which is typically deployed as a public-facing website feature accessible to unauthenticated users or customers. Because this endpoint is exposed by design to facilitate event scheduling and appointments on the public web, the attack surface is internet-facing.

Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a popular WordPress plugin used for appointment and event bookings. This flaw could allow unauthorized individuals to gain administrator-level access to WordPress sites, potentially leading to a complete compromise of the website and its data.

  • Unauthenticated users could gain administrator access.
  • This affects websites using the Amelia booking plugin.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by interacting with the booking plugin's customer update endpoint. By manipulating specific parameters, they could create a new user with elevated privileges, effectively gaining administrator access and the ability to overwrite existing administrator passwords.

  • Requires no prior authentication.
  • Triggered by manipulating customer update endpoint parameters.
  • Allows unauthenticated users to become administrators.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could potentially gain administrative control of a WordPress site. This is possible when the Booking for Appointments and Events Calendar – Amelia (Premium) plugin is used and an attacker can exploit a flaw in how customer roles are updated. The attacker could first elevate their own role to "manager" and then create a new provider linked to an administrator's user ID, ultimately overwriting the administrator's password.

  • WordPress administrator credentials.
  • Exploiting a flawed customer update endpoint.
  • Complete site takeover by an attacker.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Booking for Appointments and Events Calendar – Amelia (Premium) WordPress plugin's privilege escalation vulnerability necessitates action from platform and security teams. The immediate priority is to inventory all WordPress instances utilizing this plugin, confirm their external reachability and business criticality, identify the accountable application or platform owner, and then develop a remediation plan aligned with identified risks.

  • Platform owners should confirm plugin usage.
  • Verify plugin exposure and impact.
  • Plan coordinated updates or vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Amelia WordPress plugin?

The Amelia plugin is a premium software tool for WordPress sites used to manage appointment scheduling, event registrations, and calendar bookings. It acts as a specialized booking system that integrates directly into a website's infrastructure, allowing site visitors to book services or time slots independently.

How does CVE-2026-9055 lead to privilege escalation?

This vulnerability is classified as Improper Privilege Management (CWE-269). It occurs because the plugin fails to properly check user-supplied input in its customer update settings. An attacker can manipulate specific data fields to trick the system into promoting their account to a manager role, eventually granting them administrative control over the entire site.

What triggers this vulnerability in the Amelia plugin?

An attacker triggers the flaw by sending a crafted request to the plugin's customer update endpoint. They must specifically target the 'type' and 'externalId' parameters to force the privilege change. Simply visiting the site or viewing a calendar does not trigger the issue; the attacker must intentionally interact with this specific backend update process.

Is my site at risk according to Halo Surface Signal?

Yes, if you run the affected Amelia plugin version. Halo Surface Signal identifies this as an internet-facing risk because the booking features are designed to be publicly accessible for customer scheduling. Since the vulnerable endpoint is exposed by design for these public interactions, it is reachable by any unauthenticated attacker on the web.

How do I respond to the Amelia plugin vulnerability?

Start by identifying all WordPress sites in your environment running this plugin. Once you have a complete inventory, verify which instances are publicly reachable. Prioritize these sites for updates or vendor-recommended patches, and work with your application owners to ensure the plugin is brought to a secure, supported version.

References