CVE-2026-5465Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the `UpdateProviderCommandHandler` failing to validate changes to the `externalId` field when a Provider (Employee) user updates their own profile. The `externalId` maps directly to a WordPress user ID and is passed to `wp_set_password()` and `wp_update_user()` without authorization checks. This makes it possible for authenticated attackers, with Provider-level (Employee) access and above, to take over any WordPress account — including Administrator — by injecting an arbitrary `externalId` value when updating their own provider profile.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-07); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-04-07: 3Mentions · 2026-04-19: 2Technical Details · 2026-04-07: 3Technical Details · 2026-04-19: 204-0704-19
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-073
Disclosure3
2026-04-192
Disclosure2
Full discourse5 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5465 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2… https://www.cve.org/CVERecord?id=CVE-2026-5465 ----- Traducción: CVE-2026-5465 The… http://infoflow.cloud`

    Post summary

    The message announces CVE-2026-5465, noting an IDOR flaw in the Amelia WordPress plugin, but provides no exploit, PoC, or patch info.

    0000049
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5465 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2… https://www.cve.org/CVERecord?id=CVE-2026-5465

    Post summary

    The entry is a straightforward disclosure of CVE-2026-5465, noting an insecure direct object reference issue in the Amelia WordPress plugin.

    00000207
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5465 Insecure Direct Object Reference in Amelia WordPress Plugin Versions Up to 2.1.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5465

    Post summary

    The text announces that CVE‑2026‑5465 is an IDOR flaw affecting Amelia WordPress Plugin versions up to 2.1.3, but no exploit, patch, or active exploitation details are included.

    0000050
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5465 - Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter Intel Report: https://ift.tt/NUeRBc9

    Post summary

    The tweet announces CVE-2026-5465 affecting Amelia <=2.1.3, describing an insecure direct object reference that allows privilege escalation through the 'externalId' parameter.

    0000034
    281 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5465: HIGH] Amelia plugin for WordPress up to v2.1.3 is vulnerable to an Insecure Direct Object Reference issue. Attackers can exploit this to take control of any WordPress account.#cve,CVE-2026-5465,#cybersecurity https://cvefind.com/CVE-2026-5465

    Post summary

    The post announces a new vulnerability (CVE‑2026‑5465) in the Amelia WordPress plugin that enables an IDOR-based account takeover, but provides no PoC, exploit, or patch details.

    0000039
    619 followersView on X

Explore more