A critical privilege escalation vulnerability in the Amelia WordPress plugin, identified as CVE-2026-9055, was reportedly exploited in the wild at least one day before its public disclosure on September 2, 2026. The vulnerability affects plugin versions 8.0 through 9.6.2 and carries a CVSS score of 9.8, indicating maximum severity.
The flaw stems from insufficient validation of the "type" parameter within the customer update endpoint. This allows an attacker to manipulate their role to "manager" and initiate the creation of a new WordPress user with the "wpamelia-manager" role, specifically when the "externalId" parameter is set to 0.
Exploitation of this vulnerability enables unauthenticated attackers to escalate their privileges to that of an administrator. The attack chain involves first elevating to the manager role, then creating a provider entity linked to an existing administrator user ID, and subsequently overwriting that administrator's password.
While the CVE was published on September 2, 2026, evidence of exploitation was first reported on September 1, 2026, by VulnCheck KEV, a commercial research catalogue. This claim of exploitation has not been corroborated by other major vulnerability catalogues such as CISA KEV or EUVD ENISA. The CIRCL aggregator mirrors the VulnCheck listing but is not considered an independent verification source.
The vulnerability is categorized under CWE-269, which covers improper privilege management. The EPSS score for this vulnerability is 0.29%, placing it in the 21.9th percentile, suggesting a relatively low probability of exploitation despite its critical severity.
Users of the Amelia plugin are strongly advised to update to a patched version immediately to mitigate the risk of privilege escalation attacks.





