The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-12 06:16
Updated : 2026-09-14 21:10
NVD link : CVE-2026-77705
Mitre link : CVE-2026-77705
CVE.ORG link : CVE-2026-77705
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
