How BitFire Protects Against CVE-2026-9055 Amelia Privilege Escalation

WordPress vulnerability research

BitFire blocks automated Amelia endpoint abuse, while PRO RASP prevents unauthorized role changes and administrator password takeover.

Unauthenticated Critical Severity Administrator Takeover Privilege Escalation
BitFire · Vulnerability advisoryResearch published
AdvisoryCVE-2026-9055
ComponentBooking for Appointments and Events Calendar – Amelia (Premium)
Executive summary

What WordPress administrators need to know

CVE-2026-9055 is a critical privilege-escalation vulnerability in Booking for Appointments and Events Calendar – Amelia (Premium) versions 8.0 through 9.6.2. Researcher d.v4n_s3c reported that insufficient validation of the customer update endpoint's attacker-controlled `type` parameter lets an unauthenticated attacker become an Amelia manager. With `externalId` set to 0, the plugin creates a WordPress user with the `wpamelia-manager` role. The attacker can then create a provider linked to an administrator user ID and overwrite that administrator's password. BitFire Bot Protection blocks automated endpoint abuse, while BitFire PRO RASP blocks unauthorized privilege and protected database outcomes.

At a glance

Key facts

  • Amelia Premium versions 8.0 through 9.6.2 are affected
  • The customer update endpoint insufficiently validates the attacker-controlled type parameter
  • Setting type to manager and externalId to 0 creates a WordPress user with the wpamelia-manager role
  • A manager can create a provider linked to an administrator user ID and overwrite that administrator's password
  • The disclosed attack requires no authentication and carries a verified CVSS score of 9.8
  • BitFire Bot Protection blocks automated endpoint abuse, while PRO RASP denies protected privilege and database changes
01
Vulnerability overview

Understand the exposure

The affected component, attack path, and practical risk for WordPress websites.

Affected componentBooking for Appointments and Events Calendar – Amelia (Premium)
Potential reach<80,000 installations
Attack techniqueprivilege escalation
Published2026-09-21
BitFire breaks this takeover chain at two boundaries: automated endpoint delivery and the unauthorized privilege and database changes that follow.
02
Technical analysis

How the vulnerability works

Research details, affected versions, exploitation behavior, and remediation guidance.

What the CVE Entry Establishes

The disclosure identifies an unauthenticated privilege-escalation flaw in Amelia Premium versions 8.0 through 9.6.2. The customer update endpoint does not sufficiently validate the attacker-controlled `type` parameter. An attacker can select the manager type and set `externalId` to 0, causing creation of a WordPress account with the `wpamelia-manager` role. That role opens the second stage: creating a provider entity linked to an existing administrator user ID and overwriting the administrator's password. The result is administrator access without valid prior credentials. The entry does not specify an HTTP method, request format, source filename, or fixed version, so this article does not invent those details. Researcher d.v4n_s3c is credited with the finding.

BitFire FREE Blocks Automated Endpoint Abuse

The disclosed chain depends on interaction with Amelia's customer update endpoint, a restricted action that changes account state. BitFire FREE Bot Protection blocks known attack and scanning tools and prevents unknown or restricted bots from calling sensitive endpoints or submitting data before vulnerable plugin code runs. A client presenting as a browser must pass lightweight JavaScript verification before restricted actions; ordinary browsers normally pass, while scripts and fake browsers often fail. This directly blocks automated exploit delivery governed by that policy. It does not repair Amelia's missing validation, and an explicitly allowed bot or successfully verified client is not claimed to be stopped at this layer. Commercial sites require the appropriate BitFire license.

BitFire PRO RASP Stops Protected Takeover Outcomes

BitFire PRO RASP enforces authorization when WordPress and PHP attempt protected operations. Its database protection blocks unauthorized user creation, privilege escalation, administrator-role assignment, and protected data changes. In this chain, RASP can deny the unauthorized creation or promotion associated with the manager step and block the later attempt to overwrite an administrator's password through a provider linked to that administrator's user ID. This enforcement is based on the requester's authority at the protected operation. RASP does not sanitize `type`, change `externalId`, or claim to prevent the vulnerable endpoint from being reached; it blocks the covered privileged results that turn the validation failure into account takeover.

If Your Site Was Affected, Investigate for Persistence.

Update Amelia immediately to a release the vendor identifies as fixed; the supplied disclosure does not name a fixed version. Patching closes the known path but cannot reverse an earlier password change or remove persistence established after takeover. Run BitFire Threat Hunter to look for backdoor WordPress administrator accounts, hidden database triggers, WordPress and server cron persistence, suspicious database content, long-running PHP processes, and droppers that can restore malware or reinfect the site. Review Amelia customer, manager, and provider records for unexpected links to WordPress users. Remove every malicious account and persistence mechanism found, restore affected administrator access safely, and rotate relevant credentials. An absence of obvious malicious files does not prove the site is clean.

Deploy Layered BitFire Protection Now

CVE-2026-9055 turns weak endpoint validation into an unauthenticated administrator-takeover path. Enable BitFire Bot Protection to stop automated abuse before Amelia processes restricted actions, and deploy BitFire PRO RASP to deny unauthorized role, user, password, and administrator outcomes at runtime. Then install a vendor-confirmed fixed Amelia release and investigate every site that ran versions 8.0 through 9.6.2. Use Threat Hunter wherever prior exposure is possible. BitFire provides decisive delivery blocking, runtime containment, and post-compromise investigation without treating security controls as a substitute for patching.

03
Zero-day protection

Protection from the first exploit request

BitFire protects WordPress servers on day zero—before a vulnerability is publicly known and before other vendors have time to develop signatures or patches.

01 · VerifyStop unknown clients

Bot controls and browser verification stop untrusted automated clients before previously unknown exploit code reaches WordPress.

02 · DetectBlock malicious behavior

General WAF protections identify dangerous request behavior and hostile payloads without waiting for a vulnerability-specific signature.

03 · PreventContain attacks at runtime

RASP follows execution inside PHP and prevents unauthorized changes to protected files, accounts, and database content.

BitFire · WordPress protectionZero-day ready
BitFire combines verified-client controls, behavior-based WAF detection, and runtime RASP enforcement to protect WordPress before an exploit has a name, CVE, signature, or vendor patch.
About the author

Cory Marsh

Cory has more than 20 years of internet security experience and is a lead developer on the BitFire project.

Read BitFire security research →
Protect your WordPress website

Add protection before the next exploit arrives.

BitFire combines bot controls, request inspection, malware detection, and runtime protection in one WordPress security platform.

Protect my site free →