{"api_version":"1","generated_at":"2026-09-12T09:55:29+00:00","cve":"CVE-2026-77705","urls":{"html":"https://cve.report/CVE-2026-77705","api":"https://cve.report/api/cve/CVE-2026-77705.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-77705","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-77705"},"summary":{"title":"Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover","description":"The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-12 06:16:24","updated_at":"2026-09-12 06:16:24"},"problem_types":["CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/bfd0ce74-f91e-41fe-8288-7b1d34dd16fe/","name":"https://wpscan.com/vulnerability/bfd0ce74-f91e-41fe-8288-7b1d34dd16fe/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-77705","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77705","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Booking for Appointments and Events Calendar","version":"affected 2.4.10 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Karthik Ramakrishnan","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Booking for Appointments and Events Calendar","vendor":"Unknown","versions":[{"lessThan":"2.4.10","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Karthik Ramakrishnan"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over."}],"problemTypes":[{"descriptions":[{"description":"CWE-639 Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-12T06:00:07.938Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/bfd0ce74-f91e-41fe-8288-7b1d34dd16fe/"}],"source":{"discovery":"EXTERNAL"},"title":"Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-77705","datePublished":"2026-09-12T06:00:07.938Z","dateReserved":"2026-08-21T08:04:51.534Z","dateUpdated":"2026-09-12T06:00:07.938Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-12 06:16:24","lastModifiedDate":"2026-09-12 06:16:24","problem_types":["CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"77705","Ordinal":"1","Title":"Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover","CVE":"CVE-2026-77705","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"77705","Ordinal":"1","NoteData":"The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.","Type":"Description","Title":"Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover"}]}}}