Skip to content
Noroxi

Booking for Appointments and Events Calendar – Amelia

ameliabooking · plugin

Known security vulnerabilities for Booking for Appointments and Events Calendar – Amelia. Find out in seconds which version runs on your site with WP Lens.

29 known vulnerabilities

2 critical · 16 exploitable without logging in · 2 with public exploit code · latest Sep 12, 2026

Listed on wordpress.org · latest 2.4.11 · last updated Sep 24, 2026 · 90K+ installs

wordpress.org status checked on Oct 4, 2026

Vulnerabilities

  • CVE-2024-22298unauthenticated≤ 1.0.98

    WordPress Amelia plugin <= 1.0.98 - Broken Access Control vulnerability

    Critical 9.8
  • CVE-2026-57702unauthenticated≤ 2.4.2

    WordPress Amelia plugin <= 2.4.2 - SQL Injection vulnerability

    Critical 9.3
  • CVE-2026-48889subscriber+≤ 2.3

    WordPress Amelia plugin <= 2.3 - Privilege Escalation vulnerability

    High 8.8
  • CVE-2026-5465login required≤ 2.1.3

    Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter

    High 8.8
  • CVE-2026-2931customer+≤ 9.1.2

    Amelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change

    High 8.8
  • CVE-2026-62112editor+≤ 2.4.9

    WordPress Amelia plugin <= 2.4.9 - SQL Injection vulnerability

    High 7.6
  • CVE-2026-39487high privilege≤ 2.1.1

    WordPress Amelia plugin <= 2.1.1 - SQL Injection vulnerability

    High 7.6
  • CVE-2026-40789unauthenticated≤ 2.2

    WordPress Amelia plugin <= 2.2 - Sensitive Data Exposure vulnerability

    High 7.5
  • CVE-2025-12482unauthenticated≤ 1.2.35

    Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via search

    High 7.5
  • CVE-2026-6286unauthenticated≤ 2.2

    Booking for Appointments and Events Calendar <= 2.2 - Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission

    High 7.2
  • CVE-2026-24963high privilege≤ 1.2.38

    WordPress Amelia plugin <= 1.2.38 - Privilege Escalation vulnerability

    High 7.2
  • CVE-2024-6332unauthenticated≤ 7.7

    Booking for Appointments and Events Calendar – Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure

    Medium 6.5
  • CVE-2026-40795subscriber+≤ 2.2

    WordPress Amelia plugin <= 2.2 - Broken Access Control vulnerability

    Medium 6.5
  • CVE-2026-4668login required≤ 2.1.2

    Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter

    Medium 6.5
  • CVE-2026-10148contributor+≤ 2.4.9

    Booking for Appointments and Events Calendar – Amelia <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter

    Medium 6.4
  • CVE-2024-1484unauthenticated · needs a click≤ 1.0.98

    Booking for Appointments and Events Calendar – Amelia <= 1.0.98 - Reflected Cross-Site Scripting

    Medium 6.1
  • CVE-2023-29427unauthenticated · needs a click≤ 1.0.75

    WordPress Amelia Plugin <= 1.0.75 is vulnerable to Cross Site Scripting (XSS)

    Medium 6.1
  • CVE-2023-27918unauthenticated · needs a click

    Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.0.76 allows a remote

    Medium 6.1
  • CVE-2024-31425unauthenticated · needs a click≤ 1.0.95

    WordPress Amelia plugin <= 1.0.95 - Cross Site Request Forgery (CSRF) vulnerability

    Medium 5.4
  • CVE-2023-50860login required≤ 1.0.85

    WordPress Amelia Plugin <= 1.0.85 is vulnerable to Cross Site Scripting (XSS)

    Medium 5.4
  • CVE-2023-6808contributor+≤ 1.0.93

    Booking for Appointments and Events Calendar – Amelia <= 1.0.93 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode

    Medium 5.4
  • CVE-2026-6449unauthenticated≤ 2.1.2

    Booking for Appointments and Events Calendar – Amelia <= 2.1.2 - Unauthenticated Authorization Bypass via Remote Approval Endpoint

    Medium 5.3
  • CVE-2026-24967unauthenticated≤ 1.2.38

    WordPress Amelia plugin <= 1.2.38 - Broken Access Control vulnerability

    Medium 5.3
  • CVE-2025-14720unauthenticated≤ 1.2.38

    Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions

    Medium 5.3
  • CVE-2025-2578unauthenticated≤ 1.2.19

    Booking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure

    Medium 5.3
  • CVE-2025-26965unauthenticated≤ 1.2.16

    WordPress Amelia plugin <= 1.2.16 - Insecure Direct Object References (IDOR) vulnerability

    Medium 5.3
  • CVE-2024-6552unauthenticated≤ 1.2

    Booking for Appointments and Events Calendar – Amelia <= 1.2 - Unauthenticated Full Path Disclosure

    Medium 5.3
  • CVE-2026-14782high privilege≤ 2.4.3

    Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import

    Medium 4.9
  • CVE-2024-6225admin≤ 7.5.1

    Amelia <= 1.1.5 & Amelia (Pro) <= 7.5.1 - Authenticated (Admin+) Stored Cross-Site Scripting

    Medium 4.8

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory