CVE-2026-2931
|
| |
|
|
Affected software |
WORDPRESS |
|
|
|
The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with customer-level permissions or above to change user passwords and potentially take over administrator accounts. The vulnerability is in the pro plugin, which has the same slug. |
Link: |
| https://nvd.nist.gov/vuln/detail/CVE-2026-2931 |