CVE · High

CVE-2026-48889 — Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-48889 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4 Incorrect Privilege Assignment High 8.8 < 2.4 2.4 2026-06-02

CVE-2026-48889

The Amelia plugin for WordPress contains a security flaw affecting all versions prior to 2.4, allowing users with Subscriber-level permissions or higher to gain elevated administrative access after authentication. This vulnerability enables malicious actors to assume control beyond their intended level of authority within the affected system.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.