WordPress Plugin Vulnerabilities

Amelia Pro < 9.8 - Provider+ Arbitrary Provider Password Update via IDOR

Description

The plugin does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password and take over their account.

Proof of Concept

Affects Plugins

Fixed in 9.8

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Haitam Lazaar
Submitter
Haitam Lazaar
Verified
Yes

Timeline

Publicly Published
2026-08-24 (about 23 days ago)
Added
2026-08-24 (about 22 days ago)
Last Updated
2026-08-24 (about 22 days ago)

Other