Broken Access Control in Amelia Booking Plugin by WP Amelia
CVE-2026-40795

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
15 June 2026

What is CVE-2026-40795?

The Amelia Booking Plugin, used within WordPress, exhibits a broken access control vulnerability affecting versions up to 2.2. This flaw could allow unauthorized users to access restricted functionalities, potentially leading to data exposure or manipulation. It's essential for users of the Amelia plugin to update to the latest version to mitigate this security risk and ensure their website remains secure.

Affected Version(s)

Amelia <= 2.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Niv Kochan | Patchstack Bug Bounty Program
.