PatchSiren cyber security CVE debrief
CVE-2026-48889 TMS CVE debrief
A high-severity vulnerability, CVE-2026-48889, was discovered in the Amelia plugin, affecting versions up to 2.3. This vulnerability allows for subscriber privilege escalation, posing a significant risk to WordPress sites using the affected plugin versions.
- Vendor
- TMS
- Product
- Amelia
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-15
- Original CVE updated
- 2026-06-15
- Advisory published
- 2026-06-15
- Advisory updated
- 2026-06-15
Who should care
Administrators and security teams of WordPress sites using the Amelia plugin, especially those with subscriber roles, should be aware of this vulnerability.
Technical summary
The vulnerability, with a CVSS score of 8.8, is categorized under CWE-266. It allows attackers with low privileges to escalate their privileges, potentially leading to unauthorized access and control over the affected sites.
Defensive priority
High
Recommended defensive actions
- Update the Amelia plugin to a version beyond 2.3 to mitigate the vulnerability.
- Review and restrict subscriber privileges on WordPress sites using the Amelia plugin.
- Monitor for any suspicious activity related to privilege escalation on affected sites.
Evidence notes
Evidence from Patchstack indicates a vulnerability in the Amelia plugin, version 2.3 or earlier, allowing for subscriber privilege escalation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48889 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48889
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48889 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48889
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.