Booking for Appointments and Events Calendar – Amelia
ameliabooking · eklenti
Booking for Appointments and Events Calendar – Amelia için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.
29 bilinen açık
2 kritik · 16 kayıt giriş yapmadan sömürülebilir · 2 kayıt için istismar kodu yayımlanmış · son kayıt 12 Eyl 2026
wordpress.org'da yayında · son sürüm 2.4.11 · son güncelleme 24 Eyl 2026 · 90 bin+ kurulum
wordpress.org durumu 2 Eki 2026 tarihinde kontrol edildi
Güvenlik açıkları
- Kritik 9.8
CVE-2024-22298kimlik doğrulamasız≤ 1.0.98
WordPress Amelia plugin <= 1.0.98 - Broken Access Control vulnerability
- Kritik 9.3
CVE-2026-57702kimlik doğrulamasız≤ 2.4.2
WordPress Amelia plugin <= 2.4.2 - SQL Injection vulnerability
- Yüksek 8.8
CVE-2026-48889abone+≤ 2.3
WordPress Amelia plugin <= 2.3 - Privilege Escalation vulnerability
- Yüksek 8.8
CVE-2026-5465giriş gerekir≤ 2.1.3
Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter
- Yüksek 8.8
CVE-2026-2931müşteri+≤ 9.1.2
Amelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change
- Yüksek 7.6
CVE-2026-62112editör+≤ 2.4.9
WordPress Amelia plugin <= 2.4.9 - SQL Injection vulnerability
- Yüksek 7.6
CVE-2026-39487yüksek yetki≤ 2.1.1
WordPress Amelia plugin <= 2.1.1 - SQL Injection vulnerability
- Yüksek 7.5
CVE-2026-40789kimlik doğrulamasız≤ 2.2
WordPress Amelia plugin <= 2.2 - Sensitive Data Exposure vulnerability
- Yüksek 7.5
CVE-2025-12482kimlik doğrulamasız≤ 1.2.35
Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via search
- Yüksek 7.2
CVE-2026-6286kimlik doğrulamasız≤ 2.2
Booking for Appointments and Events Calendar <= 2.2 - Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission
- Yüksek 7.2
CVE-2026-24963yüksek yetki≤ 1.2.38
WordPress Amelia plugin <= 1.2.38 - Privilege Escalation vulnerability
- Orta 6.5
CVE-2024-6332kimlik doğrulamasız≤ 7.7
Booking for Appointments and Events Calendar – Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure
- Orta 6.5
CVE-2026-40795abone+≤ 2.2
WordPress Amelia plugin <= 2.2 - Broken Access Control vulnerability
- Orta 6.5
CVE-2026-4668giriş gerekir≤ 2.1.2
Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter
- Orta 6.4
CVE-2026-10148katılımcı+≤ 2.4.9
Booking for Appointments and Events Calendar – Amelia <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter
- Orta 6.1
CVE-2024-1484kimlik doğrulamasız · tıklama gerekir≤ 1.0.98
Booking for Appointments and Events Calendar – Amelia <= 1.0.98 - Reflected Cross-Site Scripting
- Orta 6.1
CVE-2023-29427kimlik doğrulamasız · tıklama gerekir≤ 1.0.75
WordPress Amelia Plugin <= 1.0.75 is vulnerable to Cross Site Scripting (XSS)
- Orta 6.1
CVE-2023-27918kimlik doğrulamasız · tıklama gerekir
Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.0.76 allows a remote
- Orta 5.4
CVE-2024-31425kimlik doğrulamasız · tıklama gerekir≤ 1.0.95
WordPress Amelia plugin <= 1.0.95 - Cross Site Request Forgery (CSRF) vulnerability
- Orta 5.4
CVE-2023-50860giriş gerekir≤ 1.0.85
WordPress Amelia Plugin <= 1.0.85 is vulnerable to Cross Site Scripting (XSS)
- Orta 5.4
CVE-2023-6808katılımcı+≤ 1.0.93
Booking for Appointments and Events Calendar – Amelia <= 1.0.93 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
- Orta 5.3
CVE-2026-6449kimlik doğrulamasız≤ 2.1.2
Booking for Appointments and Events Calendar – Amelia <= 2.1.2 - Unauthenticated Authorization Bypass via Remote Approval Endpoint
- Orta 5.3
CVE-2026-24967kimlik doğrulamasız≤ 1.2.38
WordPress Amelia plugin <= 1.2.38 - Broken Access Control vulnerability
- Orta 5.3
CVE-2025-14720kimlik doğrulamasız≤ 1.2.38
Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions
- Orta 5.3
CVE-2025-2578kimlik doğrulamasız≤ 1.2.19
Booking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure
- Orta 5.3
CVE-2025-26965kimlik doğrulamasız≤ 1.2.16
WordPress Amelia plugin <= 1.2.16 - Insecure Direct Object References (IDOR) vulnerability
- Orta 5.3
CVE-2024-6552kimlik doğrulamasız≤ 1.2
Booking for Appointments and Events Calendar – Amelia <= 1.2 - Unauthenticated Full Path Disclosure
- Orta 4.9
CVE-2026-14782yüksek yetki≤ 2.4.3
Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import
- Orta 4.8
CVE-2024-6225yönetici≤ 7.5.1
Amelia <= 1.1.5 & Amelia (Pro) <= 7.5.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Yetki etiketi kaydın kendi metninden okunur (ör. “abone+”: abone ve üstü roller). Metin rol söylemiyorsa CVSS'e göre “giriş gerekir” ya da “yüksek yetki” yazılır; rol adı uydurulmaz. “Tıklama gerekir”: saldırı, oturumu açık birinin bağlantıya tıklamasına bağlı (CSRF, yansıyan XSS).