THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-77705 (HIGH 7.2) — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissio

[NVD] CVE-2026-77705 (HIGH 7.2) — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissio

mednvdPublished 2026-09-12

CVE-2026-77705 CVSS: 7.2 HIGH Published: 2026-09-12T06:16:24.967

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other user

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-77705