Broken Access Control in Amelia Booking Plugin by WP Amelia
CVE-2026-40795
6.5MEDIUM
What is CVE-2026-40795?
The Amelia Booking Plugin, used within WordPress, exhibits a broken access control vulnerability affecting versions up to 2.2. This flaw could allow unauthorized users to access restricted functionalities, potentially leading to data exposure or manipulation. It's essential for users of the Amelia plugin to update to the latest version to mitigate this security risk and ensure their website remains secure.
Affected Version(s)
Amelia <= 2.2