Vulnerability in Booking for Appointments and Events Calendar – Amelia — CVE-2026-77705
MediumSeverity
0.3%Estimated exploit probability
90,000+ sitesInstalls
2.4.10Fixed in
What to do now
Update Booking for Appointments and Events Calendar – Amelia to 2.4.10 or later.
Affected versions
- Everything before 2.4.10
Affected: Booking for Appointments and Events Calendar – Amelia (plugin, ameliabooking)
What the vulnerability is
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 2.4.10. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for authenticated attackers, with custom role-level access and above, to elevate their privileges beyond those intended for their role.