## Overview
The Amelia plugin for WordPress is vulnerable to a critical privilege escalation issue. This affects versions 8.0 through 9.6.2. The vulnerability allows unauthenticated attackers to escalate their privileges.
## Technical Details
The flaw lies in the customer update endpoint, specifically in the insufficient validation of the 'type' parameter. Attackers can manipulate this parameter to set their role to 'manager'. When the 'externalId' parameter is set to 0, it triggers the creation of a WordPress user with the wpamelia-manager role. This process allows attackers to first gain manager access and then create a provider entity linked to an administrator user ID. They can subsequently overwrite the administrator's password, effectively escalating their privileges to that of an administrator.
## Impact
Successful exploitation of this vulnerability allows attackers to gain full administrative access to WordPress sites using the Amelia plugin. This can lead to unauthorized actions, data breaches, and complete control over the affected site. Given the critical CVSS score of 9.8, the risk is significant.
## Mitigation
Defenders should immediately update the Amelia plugin to version 9.6.3 or later. Regularly check for updates and apply them promptly. Additionally, monitor user roles and access logs for any unauthorized changes. Implementing strict input validation and user role management can further mitigate risks associated with this vulnerability.
CSURFACE Threat Sensor