The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record… (CVE-2026-77705)
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
AI Analysis
Technical Summary
The Booking for Appointments and Events Calendar WordPress plugin versions prior to 2.4.10 do not properly verify whether a user editing a customer or employee record has the right to modify the linked WordPress account. This lack of verification permits users with Amelia's customer or employee management permissions to change the password and email address of other users' WordPress accounts, facilitating account takeover. The vulnerability is identified as CWE-639 (Authorization Bypass Through User-Controlled Key).
Potential Impact
Successful exploitation allows an attacker with limited management permissions within the plugin to take over other WordPress user accounts by changing their passwords and email addresses. This leads to full compromise of affected user accounts, including confidentiality, integrity, and availability impacts as indicated by the CVSS score of 7.2 (high severity).
Mitigation Recommendations
Upgrade the Booking for Appointments and Events Calendar WordPress plugin to version 2.4.10 or later, where this authorization verification issue has been fixed. No other mitigation is required once the plugin is updated.
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record… (CVE-2026-77705)
Description
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
CVSS v3.1
Score 7.2high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Booking for Appointments and Events Calendar WordPress plugin versions prior to 2.4.10 do not properly verify whether a user editing a customer or employee record has the right to modify the linked WordPress account. This lack of verification permits users with Amelia's customer or employee management permissions to change the password and email address of other users' WordPress accounts, facilitating account takeover. The vulnerability is identified as CWE-639 (Authorization Bypass Through User-Controlled Key).
Potential Impact
Successful exploitation allows an attacker with limited management permissions within the plugin to take over other WordPress user accounts by changing their passwords and email addresses. This leads to full compromise of affected user accounts, including confidentiality, integrity, and availability impacts as indicated by the CVSS score of 7.2 (high severity).
Mitigation Recommendations
Upgrade the Booking for Appointments and Events Calendar WordPress plugin to version 2.4.10 or later, where this authorization verification issue has been fixed. No other mitigation is required once the plugin is updated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-67xq-jjpf-484h
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-77705"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa5effb55bf5e2cf5ef6fa6
Added to database: 09/13/2026, 00:36:11 UTC
Last enriched: 09/13/2026, 00:38:11 UTC
Last updated: 09/13/2026, 03:01:23 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.