{"api_version":"1","generated_at":"2026-08-29T12:12:04+00:00","cve":"CVE-2026-77704","urls":{"html":"https://cve.report/CVE-2026-77704","api":"https://cve.report/api/cve/CVE-2026-77704.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-77704","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-77704"},"summary":{"title":"Amelia 1.2.32 - 2.4.8 - Amelia Customer+ Appointment Status Update and Self-Approval","description":"The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were left awaiting approval and overwriting another customer's booking status on a shared appointment.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-29 06:17:44","updated_at":"2026-08-29 06:17:44"},"problem_types":["CWE-863 Incorrect Authorization"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/7b444920-28c4-4e4c-b5fd-38fdc31aef0c/","name":"https://wpscan.com/vulnerability/7b444920-28c4-4e4c-b5fd-38fdc31aef0c/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-77704","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77704","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Booking for Appointments and Events Calendar","version":"affected 1.2.32 2.4.9 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Louise","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Booking for Appointments and Events Calendar","vendor":"Unknown","versions":[{"lessThan":"2.4.9","status":"affected","version":"1.2.32","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Louise"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were left awaiting approval and overwriting another customer's booking status on a shared appointment."}],"problemTypes":[{"descriptions":[{"description":"CWE-863 Incorrect Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-29T06:00:22.631Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/7b444920-28c4-4e4c-b5fd-38fdc31aef0c/"}],"source":{"discovery":"EXTERNAL"},"title":"Amelia 1.2.32 - 2.4.8 - Amelia Customer+ Appointment Status Update and Self-Approval","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-77704","datePublished":"2026-08-29T06:00:22.631Z","dateReserved":"2026-08-21T08:04:45.568Z","dateUpdated":"2026-08-29T06:00:22.631Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-29 06:17:44","lastModifiedDate":"2026-08-29 06:17:44","problem_types":["CWE-863 Incorrect Authorization"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"77704","Ordinal":"1","Title":"Amelia 1.2.32 - 2.4.8 - Amelia Customer+ Appointment Status Upda","CVE":"CVE-2026-77704","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"77704","Ordinal":"1","NoteData":"The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were left awaiting approval and overwriting another customer's booking status on a shared appointment.","Type":"Description","Title":"Amelia 1.2.32 - 2.4.8 - Amelia Customer+ Appointment Status Upda"}]}}}