Insecure Direct Object References in Amelia Booking Plugin for WordPress
CVE-2026-2931
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 March 2026
What is CVE-2026-2931?
The Amelia Booking plugin for WordPress is susceptible to Insecure Direct Object References, allowing users to manipulate access to system resources. This flaw exists in versions up to and including 9.1.2, granting authenticated attackers with customer-level access or higher the ability to bypass authorization protocols. Consequently, they can alter user passwords, which could lead to the unauthorized takeover of administrator accounts. The vulnerability is particularly concerning in the pro version of the plugin, which maintains the same slug.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Booking for Appointments and Events Calendar β Amelia * <= 9.1.2