Booking for Appointments and Events Calendar – Amelia
ameliabooking · plugin
Known security vulnerabilities for Booking for Appointments and Events Calendar – Amelia. Find out in seconds which version runs on your site with WP Lens.
29 known vulnerabilities
2 critical · 16 exploitable without logging in · 2 with public exploit code · latest Sep 12, 2026
Listed on wordpress.org · latest 2.4.11 · last updated Sep 24, 2026 · 90K+ installs
wordpress.org status checked on Oct 4, 2026
Vulnerabilities
- Critical 9.8
CVE-2024-22298unauthenticated≤ 1.0.98
WordPress Amelia plugin <= 1.0.98 - Broken Access Control vulnerability
- Critical 9.3
CVE-2026-57702unauthenticated≤ 2.4.2
WordPress Amelia plugin <= 2.4.2 - SQL Injection vulnerability
- High 8.8
CVE-2026-48889subscriber+≤ 2.3
WordPress Amelia plugin <= 2.3 - Privilege Escalation vulnerability
- High 8.8
CVE-2026-5465login required≤ 2.1.3
Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter
- High 8.8
CVE-2026-2931customer+≤ 9.1.2
Amelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change
- High 7.6
CVE-2026-62112editor+≤ 2.4.9
WordPress Amelia plugin <= 2.4.9 - SQL Injection vulnerability
- High 7.6
CVE-2026-39487high privilege≤ 2.1.1
WordPress Amelia plugin <= 2.1.1 - SQL Injection vulnerability
- High 7.5
CVE-2026-40789unauthenticated≤ 2.2
WordPress Amelia plugin <= 2.2 - Sensitive Data Exposure vulnerability
- High 7.5
CVE-2025-12482unauthenticated≤ 1.2.35
Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via search
- High 7.2
CVE-2026-6286unauthenticated≤ 2.2
Booking for Appointments and Events Calendar <= 2.2 - Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission
- High 7.2
CVE-2026-24963high privilege≤ 1.2.38
WordPress Amelia plugin <= 1.2.38 - Privilege Escalation vulnerability
- Medium 6.5
CVE-2024-6332unauthenticated≤ 7.7
Booking for Appointments and Events Calendar – Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure
- Medium 6.5
CVE-2026-40795subscriber+≤ 2.2
WordPress Amelia plugin <= 2.2 - Broken Access Control vulnerability
- Medium 6.5
CVE-2026-4668login required≤ 2.1.2
Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter
- Medium 6.4
CVE-2026-10148contributor+≤ 2.4.9
Booking for Appointments and Events Calendar – Amelia <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter
- Medium 6.1
CVE-2024-1484unauthenticated · needs a click≤ 1.0.98
Booking for Appointments and Events Calendar – Amelia <= 1.0.98 - Reflected Cross-Site Scripting
- Medium 6.1
CVE-2023-29427unauthenticated · needs a click≤ 1.0.75
WordPress Amelia Plugin <= 1.0.75 is vulnerable to Cross Site Scripting (XSS)
- Medium 6.1
CVE-2023-27918unauthenticated · needs a click
Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.0.76 allows a remote
- Medium 5.4
CVE-2024-31425unauthenticated · needs a click≤ 1.0.95
WordPress Amelia plugin <= 1.0.95 - Cross Site Request Forgery (CSRF) vulnerability
- Medium 5.4
CVE-2023-50860login required≤ 1.0.85
WordPress Amelia Plugin <= 1.0.85 is vulnerable to Cross Site Scripting (XSS)
- Medium 5.4
CVE-2023-6808contributor+≤ 1.0.93
Booking for Appointments and Events Calendar – Amelia <= 1.0.93 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
- Medium 5.3
CVE-2026-6449unauthenticated≤ 2.1.2
Booking for Appointments and Events Calendar – Amelia <= 2.1.2 - Unauthenticated Authorization Bypass via Remote Approval Endpoint
- Medium 5.3
CVE-2026-24967unauthenticated≤ 1.2.38
WordPress Amelia plugin <= 1.2.38 - Broken Access Control vulnerability
- Medium 5.3
CVE-2025-14720unauthenticated≤ 1.2.38
Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions
- Medium 5.3
CVE-2025-2578unauthenticated≤ 1.2.19
Booking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure
- Medium 5.3
CVE-2025-26965unauthenticated≤ 1.2.16
WordPress Amelia plugin <= 1.2.16 - Insecure Direct Object References (IDOR) vulnerability
- Medium 5.3
CVE-2024-6552unauthenticated≤ 1.2
Booking for Appointments and Events Calendar – Amelia <= 1.2 - Unauthenticated Full Path Disclosure
- Medium 4.9
CVE-2026-14782high privilege≤ 2.4.3
Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import
- Medium 4.8
CVE-2024-6225admin≤ 7.5.1
Amelia <= 1.1.5 & Amelia (Pro) <= 7.5.1 - Authenticated (Admin+) Stored Cross-Site Scripting
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).