Skip to main content
QUIETLYTIC
Vulnerability

Amelia Privilege Escalation (CVE-2026-9055)

CVE-2026-9055 is a CVSS 9.8 flaw in the Amelia WordPress plugin allowing account takeover via password overwrite, reported exploited by VulnCheck.

CVE-2026-9055
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
Amelia, Melograno Booking for Appointments and Events Calendar – Amelia

CVE-2026-9055 carries a CVSS 3.1 base score of 9.8 against Amelia, a WordPress plugin published by Melograno that provides appointment and event booking functionality. NVD classifies it as CWE-269 (Improper Privilege Management) and describes a path from an ordinary customer account to full Administrator account takeover. VulnCheck’s KEV feed reports the CVE as exploited, dated September 1, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-9055 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description lays out a multi-step chain rather than a single missing check. A user registered as an ordinary customer can first escalate their own account to Amelia’s “manager” role. From there, NVD states the manager role can create a provider entity — Amelia’s internal representation of a bookable staff member or service provider — and link that provider entity to an arbitrary WordPress user ID, including an existing Administrator’s ID. Once linked, the manager-turned-provider gains the ability to overwrite the linked account’s password, which for an Administrator-linked provider means taking over that Administrator account directly.

Each step NVD describes is a privilege or data-linkage failure rather than a single injection point: the plugin does not adequately verify that a manager should be able to create arbitrary provider-to-user links, or that a provider should be able to overwrite the password of the WordPress account it’s linked to, especially when that account outranks the actor performing the action.

Evidence and confidence

  • Medium confidence — the CVSS 9.8 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-269 classification, and the full multi-step chain (customer-to-manager escalation, arbitrary provider-to-user linkage, password overwrite) all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone.
  • Unknown — exploitation probability. Our data carries no EPSS score at all for this CVE, not a low one — FIRST’s model has not scored it as of our ingestion. We report this as unscored rather than assuming a low value, since a missing score is not the same as a demonstrated low likelihood.

No field is in conflict between our two sources. Our data carries no fixed-version field.

Why this matters

This chain does not require a pre-existing privileged account or a leaked credential to start from — NVD’s own description begins with an ordinary customer registration, the kind of account any site visitor can create on a public booking page. That makes the practical barrier to entry for this vulnerability low on any Amelia-powered site that allows public account registration through its booking flow, which is the plugin’s normal, intended use.

The absence of an EPSS score is itself worth noting rather than treated as reassurance: FIRST’s model scores CVEs based on observed signals like public discussion and scanning activity, and a CVE can be unscored simply because it’s too recent for the model’s data pipeline to have caught up, not because it’s low-risk. Combined with an active VulnCheck exploitation report, sites running affected Amelia versions should treat this as urgent regardless of the missing EPSS signal.

Frequently Asked Questions

What is CVE-2026-9055? A CVSS 9.8 privilege escalation vulnerability (CWE-269) in the Amelia WordPress booking plugin, allowing an ordinary customer account to escalate to manager, link a provider entity to an arbitrary WordPress user ID, and overwrite that account’s password — enabling full Administrator takeover.

Is CVE-2026-9055 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 1, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.

Does a low EPSS score mean this is low-risk? No — there is no EPSS score for this CVE at all in our data, not a low one. An unscored CVE isn’t necessarily low-risk; it may simply be too recent for FIRST’s model to have processed.

Do I need an existing account to exploit this? No. NVD’s description states the chain begins from an ordinary customer registration, which on most Amelia-powered booking sites is open to any visitor.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

What should site operators do? Update the plugin as soon as a fix is available, and in the interim consider restricting or monitoring new customer registrations and manager-role assignments, since NVD’s chain depends on both.


Severity, vector, weakness classification, and the full privilege-escalation chain sourced from the National Vulnerability Database record for CVE-2026-9055. Exploitation status and the September 1, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. FIRST’s Exploit Prediction Scoring System has not scored this CVE as of our ingestion. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools