plugin

Ameliabooking Vulnerabilities

62 known security issues reported for the Ameliabooking WordPress plugin. Most recent disclosed Aug 27, 2026.

11 high 28 medium

Running Ameliabooking on your site? Check whether your installed version is affected.

Scan your site free

Booking for Appointments and Events Calendar <= 2.2 - Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission

high

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication bypass where the AddBookingCommand explicitly skips nonce verification (Command.php line 186), allowi...

CVSS:
7.2
Affected:
up to 2.2
Fixed in:
2.2.1
Disclosed:
Aug 27, 2026

CVE-2026-6286 on NVD →

Booking for Appointments and Events Calendar – Amelia < 2.4.6 - Authenticated (Custom role+) Information Exposure

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 2.4.6. This makes it possible for authenticated attackers, with custom role-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 2.4.6
Fixed in:
2.4.6
Disclosed:
Aug 14, 2026

CVE-2026-14213 on NVD →

Amelia Pro <= 9.6 - Insecure Direct Object Reference to Authenticated (Provider+) Customer Data Disclosure

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.6 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Custom-level access and above, to retrie...

CVSS:
4.3
Affected:
up to 9.6
Fixed in:
9.7
Disclosed:
Aug 7, 2026

CVE-2026-14211 on NVD →

Booking for Appointments and Events Calendar – Amelia < 2.4.4 - Missing Authorization

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 2.4.4. This makes it possible for authenticated attackers, with custom role-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.4.4
Fixed in:
2.4.4
Disclosed:
Aug 1, 2026

CVE-2026-14214 on NVD →

Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possi...

CVSS:
4.9
Affected:
up to 2.4.3
Fixed in:
2.4.4
Disclosed:
Jul 16, 2026

CVE-2026-14782 on NVD →

Booking for Appointments and Events Calendar – Amelia <= 2.4.2 - Unauthenticated SQL Injection

high

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...

CVSS:
7.5
Affected:
up to 2.4.2
Fixed in:
2.4.3
Disclosed:
Jul 8, 2026

CVE-2026-57702 on NVD →

Booking for Appointments and Events Calendar – Amelia <= 2.3 - Authenticated (Subscriber+) Privilege Escalation

high

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.

CVSS:
8.8
Affected:
up to 2.3
Fixed in:
2.4
Disclosed:
Jun 2, 2026

CVE-2026-48889 on NVD →

Booking for Appointments and Events Calendar – Amelia <= 2.2.1 - Unauthenticated Authorization Bypass via Remote Approval Endpoint

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.2.1. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting' status...

CVSS:
5.3
Affected:
up to 2.2.1
Fixed in:
2.3
Disclosed:
May 1, 2026

CVE-2026-6449 on NVD →

Booking for Appointments and Events Calendar – Amelia <= 2.2 - Missing Authorization

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorize...

CVSS:
4.3
Affected:
up to 2.2
Fixed in:
2.2.1
Disclosed:
Apr 28, 2026

CVE-2026-40795 on NVD →

Booking for Appointments and Events Calendar – Amelia <= 2.2 - Unauthenticated Information Exposure

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.2
Fixed in:
2.2.1
Disclosed:
Apr 23, 2026

CVE-2026-40789 on NVD →

Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter

high

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the `UpdateProviderCommandHandler` failing to validate changes to the `externalId` field when a Provider (Employee) user updates th...

CVSS:
8.8
Affected:
up to 2.1.3
Fixed in:
2.2
Disclosed:
Apr 6, 2026

CVE-2026-5465 on NVD →

Amelia - Authenticated (Manager+) SQL Injection via 'sort' Parameter vulnerability

high

Authenticated (Manager+) SQL Injection via 'sort' Parameter vulnerability

CVSS:
8.5
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Apr 1, 2026

Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter

medium

The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and including, 2.1.2. This is due to insufficient escaping on the user-supplied `sort` parameter and lack of sufficient preparati...

CVSS:
6.5
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Mar 31, 2026

CVE-2026-4668 on NVD →

Amelia - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change vulnerability

high

Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change vulnerability

CVSS:
8.8
Affected:
up to 9.1.2
Fixed in:
9.2
Disclosed:
Mar 27, 2026

Amelia Booking 8.3 - 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change

high

The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions 8.3 to 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with customer-le...

CVSS:
8.8
Affected:
8.3 – 9.1.2
Fixed in:
9.2
Disclosed:
Mar 25, 2026

CVE-2026-2931 on NVD →

Amelia <= 2.1.1 - Authenticated (Custom role+) SQL Injection

medium

The Amelia plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom role-level access and above, to...

CVSS:
6.5
Affected:
up to 2.1.1
Fixed in:
2.1.2
Disclosed:
Mar 25, 2026

CVE-2026-39487 on NVD →

Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Authenticated (Employee+) Privilege Escalation

high

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.38. This makes it possible for authenticated attackers, with employee-level access and above, to elevate their privileges to that of an administrator.

CVSS:
8.8
Affected:
up to 1.2.38
Fixed in:
2.0
Disclosed:
Mar 4, 2026

CVE-2026-24963 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] <= 1.2.38 (unfixed)

unknown

[en] Missing Authorization vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <= 1.2.38.

Affected:
up to 1.2.38
Fix:
No patched version reported
Disclosed:
Feb 3, 2026

CVE-2026-24967 on NVD →

Amelia <= 1.2.38 - Missing Authorization

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.2.38
Fixed in:
2.0
Disclosed:
Jan 11, 2026

CVE-2026-24967 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.0.0

unknown

[en] The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark payments as refunded, trigger send...

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Jan 9, 2026

CVE-2025-14720 on NVD →

Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark payments as refunded, trigger sending o...

CVSS:
5.3
Affected:
up to 1.2.38
Fixed in:
2.0.0
Disclosed:
Jan 8, 2026

CVE-2025-14720 on NVD →

Amelia 1.2.18 - 1.2.36 - Unauthenticated Sensitive Information Exposure

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 1.2.18 to 1.2.36 via the 'phpinfo' function. This makes it possible for unauthenticated attackers to extract sensitive data including server and environment configurations.

CVSS:
5.3
Affected:
1.2.18 – 1.2.36
Fixed in:
1.2.37
Disclosed:
Nov 18, 2025

CVE-2023-49282 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.2.36

unknown

[en] The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...

Affected:
up to 1.2.36
Fixed in:
1.2.36
Disclosed:
Nov 16, 2025

CVE-2025-12482 on NVD →

Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via search

high

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it p...

CVSS:
7.5
Affected:
up to 1.2.35
Fixed in:
1.2.36
Disclosed:
Nov 15, 2025

CVE-2025-12482 on NVD →

Booking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure

medium

The Booking for Appointments and Events Calendar &#8211; Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be...

CVSS:
5.3
Affected:
up to 1.2.19
Fixed in:
1.2.20
Disclosed:
Mar 27, 2025

CVE-2025-2578 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.2.17

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Amelia: from n/a through 1.2.16.

Affected:
up to 1.2.17
Fixed in:
1.2.17
Disclosed:
Feb 25, 2025

CVE-2025-26965 on NVD →

Amelia <= 1.2.16 - Unauthenticated Insecure Direct Object Reference

medium

The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.16 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.2.16
Fixed in:
1.2.17
Disclosed:
Feb 23, 2025

CVE-2025-26965 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.2.5

unknown

[en] The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the 'ameliaButtonCommand' function in all versions up to, and including, Premium 7.7 and Lite 1.2.3. This makes it possible for unauthe...

Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Sep 5, 2024

CVE-2024-6332 on NVD →

Booking for Appointments and Events Calendar – Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure

medium

The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the 'ameliaButtonCommand' function in all versions up to, and including, Premium 7.7 and Lite 1.2.4. This makes it possible for unauthentica...

CVSS:
6.5
Affected:
up to 1.2.4
Fixed in:
1.2.5
Disclosed:
Sep 4, 2024

CVE-2024-6332 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.2.1

unknown

[en] The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrie...

Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Aug 8, 2024

CVE-2024-6552 on NVD →

Booking for Appointments and Events Calendar – Amelia <= 1.2 - Unauthenticated Full Path Disclosure

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve th...

CVSS:
5.3
Affected:
up to 1.2
Fixed in:
1.2.1
Disclosed:
Aug 7, 2024

CVE-2024-6552 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.1.9

unknown

<p>WordPress Amelia Plugin <= 1.1.8 is vulnerable to Backdoor</p><p>Software: Amelia</p><p>Link: https://wordpress.org/plugins/ameliabooking/#developers</p><p>Affected Version <= 1.1.8</p>

Affected:
up to 1.1.9
Fixed in:
1.1.9
Disclosed:
Jul 3, 2024

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.1.6

unknown

[en] The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.5 (and 7.5.1 for the Pro version) due to insufficient input sanitization and output escaping. This makes it possible for authentic...

Affected:
up to 1.1.6
Fixed in:
1.1.6
Disclosed:
Jun 21, 2024

CVE-2024-6225 on NVD →

Amelia <= 1.1.5 & Amelia (Pro) <= 7.5.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.5 (and 7.5.1 for the Pro version) due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

CVSS:
4.4
Affected:
up to 1.1.5
Fixed in:
1.1.6
Disclosed:
Jun 20, 2024

CVE-2024-6225 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.99

unknown

[en] Missing Authorization vulnerability in TMS Amelia ameliabooking.This issue affects Amelia: from n/a through 1.0.98.

Affected:
up to 1.0.99
Fixed in:
1.0.99
Disclosed:
Jun 10, 2024

CVE-2024-22298 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.96

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in TMS Amelia.This issue affects Amelia: from n/a through 1.0.95.

Affected:
up to 1.0.96
Fixed in:
1.0.96
Disclosed:
Apr 15, 2024

CVE-2024-31425 on NVD →

Amelia <= 1.0.95 - Cross-Site Request Forgery

medium

The Amelia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.95. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a s...

CVSS:
4.3
Affected:
up to 1.0.95
Fixed in:
1.0.96
Disclosed:
Apr 10, 2024

CVE-2024-31425 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.99

unknown

[en] The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the date parameters in all versions up to, and including, 1.0.98 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj...

Affected:
up to 1.0.99
Fixed in:
1.0.99
Disclosed:
Mar 13, 2024

CVE-2024-1484 on NVD →

Booking for Appointments and Events Calendar – Amelia <= 1.0.98 - Reflected Cross-Site Scripting

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the date parameters in all versions up to, and including, 1.0.98 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a...

CVSS:
6.1
Affected:
up to 1.0.98
Fixed in:
1.0.99
Disclosed:
Feb 29, 2024

CVE-2024-1484 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.94

unknown

[en] The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a...

Affected:
up to 1.0.94
Fixed in:
1.0.94
Disclosed:
Feb 5, 2024

CVE-2023-6808 on NVD →

Booking for Appointments and Events Calendar – Amelia <= 1.0.93 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen...

CVSS:
6.4
Affected:
up to 1.0.93
Fixed in:
1.0.94
Disclosed:
Jan 18, 2024

CVE-2023-6808 on NVD →

Amelia <= 1.0.98 - Missing Authorization

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.98. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
6.5
Affected:
up to 1.0.98
Fixed in:
1.0.99
Disclosed:
Jan 17, 2024

CVE-2024-22298 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.86

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TMS Booking for Appointments and Events Calendar – Amelia allows Stored XSS.This issue affects Booking for Appointments and Events Calendar – Amelia: from n/a through 1.0.85.

Affected:
up to 1.0.86
Fixed in:
1.0.86
Disclosed:
Dec 28, 2023

CVE-2023-50860 on NVD →

Booking for Appointments and Events Calendar – Amelia <= 1.0.85 - Stored Cross-Site Scripting via Shortcode

medium

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen...

CVSS:
6.4
Affected:
up to 1.0.85
Fixed in:
1.0.86
Disclosed:
Dec 22, 2023

CVE-2023-50860 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.76

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in TMS Booking for Appointments and Events Calendar – Amelia plugin <= 1.0.75 versions.

Affected:
up to 1.0.76
Fixed in:
1.0.76
Disclosed:
Jun 26, 2023

CVE-2023-29427 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.76

unknown

[en] Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.0.76 allows a remote unauthenticated attacker to inject an arbitrary script by having a user who is logging in the WordPress where the product is installed visit a malicious URL.

Affected:
up to 1.0.76
Fixed in:
1.0.76
Disclosed:
May 10, 2023

CVE-2023-27918 on NVD →

Amelia <= 1.0.75 - Unauthenticated Reflected Cross-Site Scripting via 'code'

medium

The Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'code' parameter in versions up to, and including, 1.0.75 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wh...

CVSS:
6.1
Affected:
up to 1.0.75
Fixed in:
1.0.76
Disclosed:
Apr 6, 2023

CVE-2023-29427 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.48

unknown

[en] The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment history. A malicious actor can abuse this...

Affected:
up to 1.0.48
Fixed in:
1.0.48
Disclosed:
Apr 4, 2022

CVE-2022-0837 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.49

unknown

[en] The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

Affected:
up to 1.0.49
Fixed in:
1.0.49
Disclosed:
Apr 4, 2022

CVE-2022-0825 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.47

unknown

[en] The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

Affected:
up to 1.0.47
Fixed in:
1.0.47
Disclosed:
Mar 28, 2022

CVE-2022-0720 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.47

unknown

[en] The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever...

Affected:
up to 1.0.47
Fixed in:
1.0.47
Disclosed:
Mar 23, 2022

CVE-2022-0834 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.47

unknown

[en] The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack

Affected:
up to 1.0.47
Fixed in:
1.0.47
Disclosed:
Mar 21, 2022

CVE-2022-0616 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.47

unknown

[en] The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

Affected:
up to 1.0.47
Fixed in:
1.0.47
Disclosed:
Mar 21, 2022

CVE-2022-0627 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.47

unknown

[en] The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.

Affected:
up to 1.0.47
Fixed in:
1.0.47
Disclosed:
Mar 21, 2022

CVE-2022-0687 on NVD →

Appointment and Event Booking Calendar for WordPress – Amelia <= 1.0.47 - Information Disclosure and SMS Spam

medium

The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment history. A malicious actor can abuse this vuln...

CVSS:
6.4
Affected:
up to 1.0.48
Fixed in:
1.0.48
Disclosed:
Mar 14, 2022

CVE-2022-0837 on NVD →

Appointment and Event Booking Calendar for WordPress – Amelia < 1.0.49 - Arbitrary Booking Update and Sensitive Data Exposure

medium

The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

CVSS:
5.4
Affected:
up to 1.0.49
Fixed in:
1.0.49
Disclosed:
Mar 14, 2022

CVE-2022-0825 on NVD →

Amelia <= 1.0.46 - Stored Cross Site Scripting via lastName

high

The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a us...

CVSS:
7.2
Affected:
up to 1.0.46
Fixed in:
1.0.47
Disclosed:
Mar 2, 2022

CVE-2022-0834 on NVD →

Appointment and Event Booking Calendar for WordPress - Amelia < 1.0.47 - Arbitrary Booking Update and Sensitive Data Exposure

medium

The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

CVSS:
5.4
Affected:
up to 1.0.47
Fixed in:
1.0.47
Disclosed:
Mar 1, 2022

CVE-2022-0720 on NVD →

Appointment and Event Booking Calendar - Amelia < 1.0.47 - Arbitrary File Upload

high

The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.

CVSS:
8.8
Affected:
up to 1.0.47
Fixed in:
1.0.47
Disclosed:
Feb 23, 2022

CVE-2022-0687 on NVD →

Amelia <= 1.0.46 - Reflected Cross-Site Scripting

medium

The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVSS:
6.1
Affected:
up to 1.0.46
Fixed in:
1.0.47
Disclosed:
Feb 23, 2022

CVE-2022-0627 on NVD →

Amelia <= 1.0.46 - Cross-Site Request Forgery

medium

The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack

CVSS:
4.3
Affected:
up to 1.0.46
Fixed in:
1.0.47
Disclosed:
Feb 23, 2022

CVE-2022-0616 on NVD →

Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.2.20

unknown
Affected:
up to 1.2.20
Fixed in:
1.2.20

CVE-2025-2578 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database