CVE-2026-2931Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with customer-level permissions or above to change user passwords and potentially take over administrator accounts. The vulnerability is in the pro plugin, which has the same slug.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-26); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-26: 4Mentions · 2026-03-27: 1Technical Details · 2026-03-26: 4Technical Details · 2026-03-27: 103-2603-27
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-264
Disclosure3General1
2026-03-271
Disclosure1
Full discourse5 posts
  • Black Lantern Security (BLSOPS)@BlackLanternLLC
    Disclosure

    From customer to admin takeover in one request—Amelia Booking Pro flaw enables full WordPress compromise. #CVE-2026-2931 is on the BLS Blog now! https://blog.blacklanternsecurity.com/p/amelia-booking-pro-912-authenticated

    Post summary

    The post announces CVE-2026-2931, detailing an admin takeover flaw in Amelia Booking Pro, but provides no exploit code or mitigation information.

    0102097
    655 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-2931 The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing … https://www.cve.org/CVERecord?id=CVE-2026-2931

    Post summary

    The post reports CVE-2026-2931 affecting Amelia Booking plugin as an IDOR flaw, but contains no PoC, exploit, patch, or evidence of active exploitation.

    00010105
    56.8K followersView on X
  • Nxploited@Nxploited
    Disclosure

    Amelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change CVE-2026-2931 Channel: https://t.me/KNxploited #CyberSecurity #WordPress #Vulnerability #Exploit #PrivilegeEscalation #Infosec #BugBounty https://t.co/Fi2VAe88KG

    Post summary

    This tweet announces a new IDOR vulnerability (CVE-2026-2931) in Amelia Booking 9.1.2 that allows authenticated users to change any user's password; no PoC, exploit code, or patch is provided.

    0000072
    94 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2931: HIGH] Amelia Booking plugin for WordPress versions up to 9.1.2 has an Insecure Direct Object References vulnerability, allowing authenticated attackers to alter passwords & potentially take ove...#cve,CVE-2026-2931,#cybersecurity https://cvefind.com/CVE-2026-2931

    Post summary

    The post discloses a high‑severity IDOR vulnerability in Amelia Booking plugin versions up to 9.1.2, enabling authenticated attackers to modify passwords and potentially take system control.

    0000052
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-2931 - High The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access t... https://www.thehackerwire.com/vulnerability/CVE-2026-2931/ https://t.co/moabUrNYmO

    Post summary

    A security advisory identifies a high‑severity Insecure Direct Object Reference vulnerability in Amelia Booking plugin versions up to 9.1.2. The post provides the CVE ID, severity, affected plugin and version, but does not mention exploits, PoC, or patches.

    0000060
    148 followersView on X

Explore more