{"error":0,"message":null,"data":{"name":"Booking for Appointments and Events Calendar &#8211; Amelia","plugin":"ameliabooking","link":"https:\/\/wordpress.org\/plugins\/ameliabooking\/","latest":"1788937320","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"be58b3c6776b18ad15056aa745b6c443e79cf44264304a889edf4f3ecb0d5a37","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.47","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.47","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0616","name":"CVE-2022-0616","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0616","description":"[en] The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack","date":"2022-03-21"},{"id":"5b975dfce3426159ec25fe7503c5977db43fd6cb","name":"WordPress Amelia plugin <= 1.0.45 - Arbitrary Customer Deletion via Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-0-45-arbitrary-customer-deletion-via-cross-site-request-forgery-csrf-vulnerability","description":"Arbitrary Customer Deletion via Cross-Site Request Forgery (CSRF) vulnerability discovered by Muhamad Hidayat in WordPress Amelia plugin (versions <= 1.0.45).","date":"2022-02-23"},{"id":"7c63d76e-34ca-4778-8784-437d446c16e0","name":"Amelia &lt; 1.0.46 - Arbitrary Customer Deletion via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/7c63d76e-34ca-4778-8784-437d446c16e0","description":"The plugin does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack","date":null},{"id":"d1766bf283d369b48632adcd63a5002dcd7b87f2","name":"Amelia <= 1.0.46 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/amelia-1046-cross-site-request-forgery","description":"The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack","date":"2022-02-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"e579fd352ac315f7665051f7a59c2b4134bb3d87c8de0e3fee1a602ea427b709","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.47","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.47","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0627","name":"CVE-2022-0627","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0627","description":"[en] The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.","date":"2022-03-21"},{"id":"ef2cf4955dd98595de9c08c194c827917954282c","name":"WordPress Amelia plugin <= 1.0.45 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-0-45-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by Ran Crane in WordPress Amelia plugin (versions <= 1.0.45).","date":"2022-02-23"},{"id":"fd8c720a-a94a-438f-b686-3a734e3c24e4","name":"Amelia &lt; 1.0.46 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/fd8c720a-a94a-438f-b686-3a734e3c24e4","description":"The plugin does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.","date":null},{"id":"7ef4bbc409a7174f68465f227c90880737330e2e","name":"Amelia <= 1.0.46 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/amelia-1046-reflected-cross-site-scripting","description":"The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.","date":"2022-02-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"57f047213a0b04d8981f053bd074ef21a088c904896d0b26b3f1318a14779ad5","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.47","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.47","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0687","name":"CVE-2022-0687","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0687","description":"[en] The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom \"Amelia Manager\" role.","date":"2022-03-21"},{"id":"fb50f7e4c5cd2ce1660df5c0d4b48cdb8c15da38","name":"WordPress Amelia plugin <= 1.0.45 - Remote Code Execution (RCE) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-0-45-remote-code-execution-rce-vulnerability","description":"Remote Code Execution (RCE) vulnerability discovered by qerogram in WordPress Amelia plugin (versions <= 1.0.45).","date":"2022-02-23"},{"id":"3cf05815-9b74-4491-a935-d69a0834146c","name":"Amelia &lt; 1.0.46 - Manager+ RCE","link":"https:\/\/wpscan.com\/vulnerability\/3cf05815-9b74-4491-a935-d69a0834146c","description":"The plugin stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom &quot;Amelia Manager&quot; role.","date":null},{"id":"9b84b0ba8cee61a226bcc65fbe8af2e8532adebb","name":"Appointment and Event Booking Calendar - Amelia < 1.0.47 - Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/appointment-and-event-booking-calendar-amelia-1047-arbitrary-file-upload","description":"The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom \"Amelia Manager\" role.","date":"2022-02-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}]}},{"uuid":"57dd3e80354607cb41b1afbd1261341e0c54d73ec703b0c7b30ec4751f48426c","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.47","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.47","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0720","name":"CVE-2022-0720","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0720","description":"[en] The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.","date":"2022-03-28"},{"id":"67f78cebae26644a01e2509115121cbbe7a45888","name":"WordPress Amelia plugin <= 1.0.46 - Arbitrary Appointments Update and Sensitive Data Disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-0-46-arbitrary-appointments-update-and-sensitive-data-disclosure-vulnerability","description":"Arbitrary Appointments Update and Sensitive Data Disclosure vulnerability discovered by Huli (Cymetrics) in WordPress Amelia plugin (versions <= 1.0.46).","date":"2022-03-01"},{"id":"435ef99c-9210-46c7-80a4-09cd4d3d00cf","name":"Amelia &lt; 1.0.47 - Customer+ Arbitrary Appointments Update and Sensitive Data Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/435ef99c-9210-46c7-80a4-09cd4d3d00cf","description":"The plugin does not have proper authorisation when managing appointments, allowing any customer to update other&#039;s booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.","date":null},{"id":"f5390c61462bf7509ed388a145641c9e608c3805","name":"Appointment and Event Booking Calendar for WordPress - Amelia < 1.0.47 - Arbitrary Booking Update and Sensitive Data Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/appointment-and-event-booking-calendar-for-wordpress-amelia-1047-arbitrary-booking-update-and-sensitive-data-exposure","description":"The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.","date":"2022-03-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.8","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.5"},"cwe":[{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}]}},{"uuid":"35d7255e5486b337ca153d35ae59f363f8f4bc26a37faff3cd713d7b24ef5525","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.49","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.49","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0825","name":"CVE-2022-0825","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0825","description":"[en] The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.","date":"2022-04-04"},{"id":"eb42c8d209c1173fd3cc101aaa4d1919b90cc69d","name":"WordPress Amelia plugin <= 1.0.48 - Arbitrary Appointments Status Update vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-0-48-arbitrary-appointments-status-update-vulnerability","description":"Arbitrary Appointments Status Update vulnerability discovered by Huli from Cymetrics in WordPress Amelia plugin (versions <= 1.0.48).","date":"2022-03-14"},{"id":"1a92a65f-e9df-41b5-9a1c-8e24ee9bf50e","name":"Amelia &lt; 1.0.49 - Customer+ Arbitrary Appointments Status Update","link":"https:\/\/wpscan.com\/vulnerability\/1a92a65f-e9df-41b5-9a1c-8e24ee9bf50e","description":"The plugin does not have proper authorisation when managing appointments, allowing any customer to update other&#039;s booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.","date":null},{"id":"574f598fcfa317ab4dda807d11b266064472288f","name":"Appointment and Event Booking Calendar for WordPress \u2013 Amelia < 1.0.49 - Arbitrary Booking Update and Sensitive Data Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/appointment-and-event-booking-calendar-for-wordpress-amelia-1049-arbitrary-booking-update-and-sensitive-data-exposure","description":"The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.","date":"2022-03-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.8","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.5"},"cwe":[{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}]}},{"uuid":"f6feb98c4aaa1113b10a23ea6314d988f457f78c1717f2ceacece992a933932c","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.47","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.47","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0834","name":"CVE-2022-0834","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0834","description":"[en] The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~\/src\/Application\/Controller\/User\/Customer\/AddCustomerController.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user accesses the booking calendar with the date the attacker has injected the malicious payload into. This affects versions up to and including 1.0.46.","date":"2022-03-23"},{"id":"1e618e985f8b53bb355bfc0e8b0d1e75e8a56aca","name":"WordPress Amelia plugin <= 1.0.46 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-0-46-unauthenticated-stored-cross-site-scripting-xss-vulnerability","description":"Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Vinay Kumar (Trellix) in WordPress Amelia plugin (versions <= 1.0.46).","date":"2022-03-02"},{"id":"0107553b-4038-4e86-a869-86665c8bcba9","name":"Amelia &lt; 1.0.47 - Unauthenticated Stored XSS via lastName","link":"https:\/\/wpscan.com\/vulnerability\/0107553b-4038-4e86-a869-86665c8bcba9","description":"The plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~\/src\/Application\/Controller\/User\/Customer\/AddCustomerController.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user accesses the booking calendar with the date the attacker has injected the malicious payload into.","date":null},{"id":"05f63bdf0faab8ee412c5614f10b0516f0ae638b","name":"Amelia <= 1.0.46 - Stored Cross Site Scripting via lastName","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/amelia-1046-stored-cross-site-scripting-via-lastname","description":"The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~\/src\/Application\/Controller\/User\/Customer\/AddCustomerController.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user accesses the booking calendar with the date the attacker has injected the malicious payload into. This affects versions up to and including 1.0.46.","date":"2022-03-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f07cd7e5a2701b8061b159611424e0dd4c2d215d1e831fba1f8c2a1000b3553a","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.48","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.48","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0837","name":"CVE-2022-0837","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0837","description":"[en] The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment history. A malicious actor can abuse this vulnerability to drain out the account balance by keep sending SMS notification.","date":"2022-04-04"},{"id":"a7f50a689c6b83d1a3034148664001bda86edbc3","name":"WordPress Amelia plugin <= 1.0.47 - SMS Service Abuse and Sensitive Data Disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-0-47-sms-service-abuse-and-sensitive-data-disclosure-vulnerability","description":"SMS Service Abuse and Sensitive Data Disclosure vulnerability discovered by Huli (Cymetrics) in WordPress Amelia plugin (versions <= 1.0.47).","date":"2022-03-14"},{"id":"0882e5c0-f319-4994-9346-aa18438fda6a","name":"Amelia &lt; 1.0.48 - Customer+ SMS Service Abuse and Sensitive Data Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/0882e5c0-f319-4994-9346-aa18438fda6a","description":"The plugin does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment history. A malicious actor can abuse this vulnerability to drain out the account balance by keep sending SMS notification.","date":null},{"id":"b10cef4386a727504eb66dcfa8861dca33ebd46b","name":"Appointment and Event Booking Calendar for WordPress \u2013 Amelia <= 1.0.47 - Information Disclosure and SMS Spam","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/appointment-and-event-booking-calendar-for-wordpress-amelia-1047-information-disclosure-and-sms-spam","description":"The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment history. A malicious actor can abuse this vulnerability to drain out the account balance by keep sending SMS notification.","date":"2022-03-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.8","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.5"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}},{"uuid":"16123045c92ec78479c9a833320f6b0093cb10aae0a095c20c84691657494cd6","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.76","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.76","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-29427","name":"CVE-2023-29427","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-29427","description":"[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in TMS Booking for Appointments and Events Calendar \u2013 Amelia plugin <=\u00a01.0.75 versions.","date":"2023-06-26"},{"id":"f066e2b916e78e7e18b7a3c8256d9d799088e527","name":"WordPress  Amelia Plugin  <= 1.0.75 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-0-75-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Amelia plugin to the latest available version (at least 1.0.76).\nminhtuanact discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 1.0.76.","date":"2023-04-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ec6be2b3916e0612f89af6ca3e04a496caad51d6b39cf041852e1bf7cdc8c31b","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.76","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.76","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-27918","name":"CVE-2023-27918","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-27918","description":"[en] Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.0.76 allows a remote unauthenticated attacker to inject an arbitrary script by having a user who is logging in the WordPress where the product is installed visit a malicious URL.","date":"2023-05-10"},{"id":"JVNDB-2023-000040","name":"WordPress Plugin \"Appointment and Event Booking Calendar for WordPress - Amelia\" vulnerable to cross-site scripting","link":"http:\/\/jvndb.jvn.jp\/jvndb\/JVNDB-2023-000040","description":"WordPress Plugin \"Appointment and Event Booking Calendar for WordPress - Amelia\" provided by TMS contains a cross-site scripting vulnerability (CWE-79).  Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to the developer and coordinated. The developer and JPCERT\/CC published respective advisories in order to notify users of this vulnerability.","date":"2023-04-24"},{"id":"60a34cbeea883e4a907428e0db9d21df8fd5c27a","name":"Amelia <= 1.0.75 - Unauthenticated Reflected Cross-Site Scripting via 'code'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/amelia-1075-unauthenticated-reflected-cross-site-scripting-via-code","description":"The Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'code' parameter in versions up to, and including, 1.0.75 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2023-27918 may be a duplicate.","date":"2023-04-06"},{"id":"7ce4a814-4028-45b8-b4c7-2ff76f537eb2","name":"Appointment and Event Booking Calendar for WordPress &lt; 1.0.76 - Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/7ce4a814-4028-45b8-b4c7-2ff76f537eb2","description":"The plugin does not sanitise and escape the code parameter before outputting it back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2dac0dc4c2644f33ef164f385e4c5bed738e9b123dbd4918a90e4614220ea951","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.86","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.86","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-50860","name":"CVE-2023-50860","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-50860","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TMS Booking for Appointments and Events Calendar \u2013 Amelia allows Stored XSS.This issue affects Booking for Appointments and Events Calendar \u2013 Amelia: from n\/a through 1.0.85.","date":"2023-12-28"},{"id":"37ddd7ec6c8559eb11b1867d20e9d4a0a73a4577","name":"WordPress  Amelia Plugin  <= 1.0.85 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-0-85-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Amelia plugin to the latest available version (at least 1.0.86).\nNg\u00f4 Thi\u00ean An (ancorn_ from VNPT-VCI) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 1.0.86.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-22"},{"id":"45609dbc16577f9bcfd6817825f2c77a6c40455b","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 1.0.85 - Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-1085-stored-cross-site-scripting-via-shortcode","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-12-22"},{"id":"55c7d5fa-f2a8-4762-8920-cf48464f3e04","name":"Booking for Appointments and Events Calendar &ndash; Amelia &lt; 1.0.86 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/55c7d5fa-f2a8-4762-8920-cf48464f3e04","description":"The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page\/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"80b9c6404680ebeaa947d95a96aa7049620106e7de364159c784877880eebefb","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.94","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.94","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6808","name":"CVE-2023-6808","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6808","description":"[en] The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-05"},{"id":"013a6fd4b7696e5618ccbada29d1ec2f68801764","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 1.0.93 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-1093-authenticatedcontributor-stored-cross-site-scripting-via-shortcode","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-01-18"},{"id":"3f2fecb2b74fe60271011e9a97614c206d133117","name":"WordPress  Amelia Plugin  <= 1.0.93 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-0-93-authenticated-contributor-stored-cross-site-scripting-via-shortcode-vulnerability","description":"Update the WordPress Amelia plugin to the latest available version (at least 1.0.94).\nNg\u00f4 Thi\u00ean An (ancorn_) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 1.0.94.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-19"},{"id":"6f0b0586-1efc-4555-ace2-8c1b8017af8e","name":"Booking for Appointments and Events Calendar &ndash; Amelia &lt; 1.0.94 - Contributor+ Stored Cross-Site Scripting via shortcode","link":"https:\/\/wpscan.com\/vulnerability\/6f0b0586-1efc-4555-ace2-8c1b8017af8e","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s shortcode(s) in all versions up to, and including, 1.0.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"dbc241f5dda8345a2ca598ebbd5d4fa13cb33f3f42d813f090112317ae0de106","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.99","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.99","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-22298","name":"CVE-2024-22298","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-22298","description":"[en] Missing Authorization vulnerability in TMS Amelia ameliabooking.This issue affects Amelia: from n\/a through 1.0.98.","date":"2024-06-10"},{"id":"3d330002bad85b9ea420349dae31a2a2b9636127","name":"WordPress  Amelia Plugin  <= 1.0.96 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-0-96-broken-access-control-vulnerability","description":"No patched version is available.\nAbdi Pranata discovered and reported this Broken Access Control vulnerability in WordPress Amelia Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has not been known to be fixed yet.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-17"},{"id":"71a300349476c03d467accc06579573852cb046f","name":"Amelia <= 1.0.98 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/amelia-1096-missing-authorization","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.98. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2024-01-17"},{"id":"c12f545d-db15-4238-bf00-225d692d38d6","name":"Amelia &lt; 1.0.99 - Missing Authorization","link":"https:\/\/wpscan.com\/vulnerability\/c12f545d-db15-4238-bf00-225d692d38d6","description":"The plugin is vulnerable to unauthorized access due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"026e87bf50f9c268ff46c88bca28ad03b15bc708cfafe46839ba3b1206ee9ed0","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.99","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.99","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1484","name":"CVE-2024-1484","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1484","description":"[en] The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the date parameters in all versions up to, and including, 1.0.98 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-03-13"},{"id":"943ca30fb2c8e4e97d0377f09e096266eed3c78d","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 1.0.98 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-1098-reflected-cross-site-scripting","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the date parameters in all versions up to, and including, 1.0.98 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-02-29"},{"id":"b36f2ecf544e0232701f0384c9f4790a4bc1450c","name":"WordPress  Amelia Plugin    <= 1.0.98 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-0-98-reflected-cross-site-scripting-vulnerability","description":"Update the WordPress Amelia plugin to the latest available version (at least 1.0.99).\nMuhammad Hassham Nagori discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 1.0.99.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"72ab41e5-849a-4fcd-8a5b-b049ff21b5c8","name":"Booking for Appointments and Events Calendar &ndash; Amelia &lt; 1.0.99 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/72ab41e5-849a-4fcd-8a5b-b049ff21b5c8","description":"The Booking for Appointments and Events Calendar &ndash; Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the date parameters in all versions up to, and including, 1.0.98 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"32ae6c9fb13e01bcc7b3311c7201ae84157a5a9adc3cacf10f2c885b637a9fdf","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.0.96","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.96","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-31425","name":"CVE-2024-31425","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-31425","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in TMS Amelia.This issue affects Amelia: from n\/a through 1.0.95.","date":"2024-04-15"},{"id":"7267fc32108460da0b1071b0cc668fcbdd361e47","name":"WordPress  Amelia Plugin    <= 1.0.95 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-0-95-cross-site-request-forgery-csrf-vulnerability","description":"Update the WordPress Amelia plugin to the latest available version (at least 1.0.96).\nYudistira Arya discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 1.0.96.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"080b53ade05486297e3f348d541471881a37588b","name":"Amelia <= 1.0.95 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/amelia-1095-cross-site-request-forgery","description":"The Amelia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.95. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-04-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"2.5"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a3aa7a6e24cc4a228a86f42554cd4018933a296e42d7b8da3ff9ef405fbadd70","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.1.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6225","name":"CVE-2024-6225","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6225","description":"[en] The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.5 (and 7.5.1 for the Pro version) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-06-21"},{"id":"d0b8efe6a39c438ee52fe5b6aa9eacb7d59058f2","name":"WordPress Amelia Plugin <= 1.1.5 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-1-5-and-7-5-1-authenticated-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Amelia Plugin <= 1.1.5 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Amelia<\/p><p>Link: https:\/\/wordpress.org\/plugins\/ameliabooking\/#developers<\/p><p>Affected Version <= 1.1.5<\/p><p>Fixed in version 1.1.6 <\/p>","date":"2024-06-20"},{"id":"2469ed93aeaaed929b86ca97e33dca1302b2ae98","name":"Amelia <= 1.1.5 & Amelia (Pro) <= 7.5.1  - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/amelia-115-amelia-pro-751-authenticated-admin-stored-cross-site-scripting","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.5 (and 7.5.1 for the Pro version) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-06-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"69449b07e825351be7151ec79a917a04d07bb524bae81b2bc1208fe53f0da78f","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.1.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9cc740a021c4cab3af1b4bdaf20e66d30052fbf6","name":"WordPress Amelia Plugin <= 1.1.8 is vulnerable to Backdoor","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-1-8-malicious-polyfill-io-embed-vulnerability","description":"<p>WordPress Amelia Plugin <= 1.1.8 is vulnerable to Backdoor<\/p><p>Software: Amelia<\/p><p>Link: https:\/\/wordpress.org\/plugins\/ameliabooking\/#developers<\/p><p>Affected Version <= 1.1.8<\/p>","date":"2024-07-03"}],"impact":[]},{"uuid":"ef93df1662324ca4b84a6f14305585822f9acc001f9c1c1290b325dc608144e2","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6552","name":"CVE-2024-6552","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6552","description":"[en] The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.","date":"2024-08-08"},{"id":"23133e623385e925ea39559965d7f930146762a3","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 1.2 - Unauthenticated Full Path Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-12-unauthenticated-full-path-disclosure","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.","date":"2024-08-07"},{"id":"b6d7c6d340e2a562c384695f71d34a2b707daadc","name":"WordPress Amelia Plugin <= 1.2 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-2-unauthenticated-full-path-disclosure-vulnerability","description":"<p>WordPress Amelia Plugin <= 1.2 is vulnerable to Sensitive Data Exposure<\/p><p>Software: Amelia<\/p><p>Link: https:\/\/wordpress.org\/plugins\/ameliabooking\/#developers<\/p><p>Affected Version <= 1.2<\/p><p>Fixed in version 1.2.1 <\/p>","date":"2024-08-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"745a62c712a4c287aa69f0619be2018b73f4f0150ca9ce316f197569d53ac733","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6332","name":"CVE-2024-6332","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6332","description":"[en] The Booking for Appointments and Events Calendar \u2013 Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the 'ameliaButtonCommand' function in all versions up to, and including, Premium 7.7 and Lite 1.2.3. This makes it possible for unauthenticated attackers to access employee calendar details, including Google Calendar OAuth tokens in the premium version.","date":"2024-09-05"},{"id":"9f2bd5624297b3992b856d5ca3aabb28d4237656","name":"Booking for Appointments and Events Calendar \u2013 Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/booking-for-appointments-and-events-calendar-amelia-premium-77-and-lite-123-missing-authorization-to-sensitive-information-exposure","description":"The Booking for Appointments and Events Calendar \u2013 Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the 'ameliaButtonCommand' function in all versions up to, and including, Premium 7.7 and Lite 1.2.4. This makes it possible for unauthenticated attackers to access employee calendar details, including Google Calendar OAuth tokens in the premium version.","date":"2024-09-04"},{"id":"0592f7be48de09be911f02a702d72634888e28fc","name":"WordPress Amelia Plugin <= 1.2.3 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-2-3-missing-authorization-to-sensitive-information-exposure-vulnerability","description":"<p>WordPress Amelia Plugin <= 1.2.3 is vulnerable to Broken Access Control<\/p><p>Affected Version <= 1.2.3<\/p>","date":"2024-09-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"6.5","severity":"m","exploitable":"3.9","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"3.9","impact":"2.5"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8d6d19579ec3efbe3cf3a11712ec7a9d0542e31ebc9d5d63c9bbd811afb835d6","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.2.17","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.17","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-26965","name":"CVE-2025-26965","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-26965","description":"[en] Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n\/a through <= 1.2.16.","date":"2025-02-25"},{"id":"f4bce094d2bb78604c2ae3e65ac99d84e3d93977","name":"WordPress Amelia Plugin <= 1.2.16 is vulnerable to Insecure Direct Object References (IDOR)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ameliabooking\/vulnerability\/wordpress-amelia-plugin-1-2-16-insecure-direct-object-references-idor-vulnerability","description":"<p>WordPress Amelia Plugin <= 1.2.16 is vulnerable to Insecure Direct Object References (IDOR)<\/p><p>Software: Amelia<\/p><p>Fixed in version 1.2.17 <\/p><p>Affected Version <= 1.2.16<\/p><p>CVE: CVE-2025-26965<\/p>","date":"2025-02-23"},{"id":"60efd969d0391ccd210b8706f0ac3e45a429f251","name":"Amelia <= 1.2.16 - Unauthenticated Insecure Direct Object Reference","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking-2\/amelia-1216-unauthenticated-insecure-direct-object-reference","description":"The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.16 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2025-02-23"},{"id":"EUVD-2025-5441","name":"EUVD-2025-5441","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-5441","description":"Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Amelia: from n\/a through 1.2.16.","date":"2025-02-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"040643e1e6d834c173e32bb82ad1c0b201c74253369a8388d998365e7948a6e3","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.2.20","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.20","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-2578","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-2578","description":"The Booking for Appointments and Events Calendar &#8211; Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.","date":"0000-00-00"},{"id":"5ef8b2246ebd5b79cc28155cade9c15cfb6ab651","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking-2\/booking-for-appointments-and-events-calendar-amelia-1219-unauthenticated-full-path-disclosure","description":"The Booking for Appointments and Events Calendar &#8211; Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.","date":"2025-03-27"},{"id":"EUVD-2025-8554","name":"EUVD-2025-8554","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-8554","description":"The Booking for Appointments and Events Calendar &#8211; Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.","date":"2025-03-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"428cbb20773a902d0e7cdb439e5f29121374dd28b5af67ad1bfbe2c16fa51dd3","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.2.36","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.36","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-12482","name":"CVE-2025-12482","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-12482","description":"[en] The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to SQL Injection via the \u2018search\u2019 parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-11-16"},{"id":"ec87a2668d79eef4a776647643336b4d614a2cdd","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 1.2.35 - Unauthenticated SQL Injection via search","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-1235-unauthenticated-sql-injection-via-search","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to SQL Injection via the \u2018search\u2019 parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-11-15"},{"id":"EUVD-2025-197716","name":"EUVD-2025-197716","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-197716","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to SQL Injection via the \u2018search\u2019 parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-11-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"3cb18dedba9efb128f3499c6d36c61c86c868cb0faffc7b28e43f44b495296a6","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-14720","name":"CVE-2025-14720","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-14720","description":"[en] The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark payments as refunded, trigger sending of queued notifications (emails\/SMS\/WhatsApp), and access debug information among other things.","date":"2026-01-09"},{"id":"5b90f702a1afcab3768803d35e6c2f03a8edcf9f","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-1238-missing-authorization-to-unauthenticated-multiple-ajax-actions","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark payments as refunded, trigger sending of queued notifications (emails\/SMS\/WhatsApp), and access debug information among other things.","date":"2026-01-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"da4679534397e8ef087ff9f7ecdaecb43049cd53f6dd713370785dabd891f0ea","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-24967","name":"CVE-2026-24967","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-24967","description":"[en] Missing Authorization vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n\/a through <= 1.2.38.","date":"2026-02-03"},{"id":"b0d61f74f3030f975c7cc8441314afbac8148c38","name":"Amelia <= 1.2.38 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/amelia-1238-missing-authorization","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-01-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"20c25278090e26d555088056866462fdd86e66577b7a437f2d919b12bdf9272e","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-24963","name":"CVE-2026-24963","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-24963","description":"[en] Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issue affects Amelia: from n\/a through <= 1.2.38.","date":"2026-03-05"},{"id":"925ec69c745ec808c1b057757a31788c50dbd6cd","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 1.2.38 - Authenticated (Employee+) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-1238-authenticated-employee-privilege-escalation","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.38. This makes it possible for authenticated attackers, with employee-level access and above, to elevate their privileges to that of an administrator.","date":"2026-03-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-266","name":"Incorrect Privilege Assignment","description":"A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"ac7b2dd770cd4ec19b6f5ba1438e6280516cd3cbc9bc9bdb3ad96117ef7e0d2e","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-4668","name":"Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-4668","description":"The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and including, 2.1.2. This is due to insufficient escaping on the user-supplied `sort` parameter and lack of sufficient preparation on the existing SQL query in `PaymentRepository.php`, where the sort field is interpolated directly into an ORDER BY clause without sanitization or whitelist validation. PDO prepared statements do not protect ORDER BY column names. GET requests also skip Amelia's nonce validation entirely. This makes it possible for authenticated attackers, with Manager-level (`wpamelia-manager`) access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via time-based blind SQL injection.","date":"0000-00-00"},{"id":"3879c3588b65aa3b444f15d62edd5d369bf80548","name":"Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/amelia-212-authenticated-manager-sql-injection-via-sort-parameter","description":"The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and including, 2.1.2. This is due to insufficient escaping on the user-supplied `sort` parameter and lack of sufficient preparation on the existing SQL query in `PaymentRepository.php`, where the sort field is interpolated directly into an ORDER BY clause without sanitization or whitelist validation. PDO prepared statements do not protect ORDER BY column names. GET requests also skip Amelia's nonce validation entirely. This makes it possible for authenticated attackers, with Manager-level (`wpamelia-manager`) access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via time-based blind SQL injection.","date":"2026-03-31"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1bffd5ff3374e140ab8276b67d763ee6de179d72b6d2e63e0ea9664090ba96c8","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.1.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-39487","name":"CVE-2026-39487","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-39487","description":"[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n\/a through <= 2.1.1.","date":"2026-04-08"},{"id":"45435a99459bdebc09cdc3ae606dd9c9938e8c07","name":"Amelia <= 2.1.1 - Authenticated (Custom role+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/amelia-211-authenticated-custom-role-sql-injection","description":"The Amelia plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom role-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-03-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:N\/A:L","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"h","i":"n","a":"l","score":"7.6","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:N\/A:L","score":"7.6","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"changed","c":"high","i":"none","a":"low","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"72d5b6f8236ce0898da2e9b798522d4259f31aa37c0f41aee5021b36b1f8997c","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5465","name":"Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5465","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the `UpdateProviderCommandHandler` failing to validate changes to the `externalId` field when a Provider (Employee) user updates their own profile. The `externalId` maps directly to a WordPress user ID and is passed to `wp_set_password()` and `wp_update_user()` without authorization checks. This makes it possible for authenticated attackers, with Provider-level (Employee) access and above, to take over any WordPress account \u2014 including Administrator \u2014 by injecting an arbitrary `externalId` value when updating their own provider profile.","date":"0000-00-00"},{"id":"8e3b915f61a03a82dbe580cb0862b01c38c35021","name":"Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/amelia-213-insecure-direct-object-reference-to-authenticated-employee-privilege-escalation-via-externalid-parameter","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the `UpdateProviderCommandHandler` failing to validate changes to the `externalId` field when a Provider (Employee) user updates their own profile. The `externalId` maps directly to a WordPress user ID and is passed to `wp_set_password()` and `wp_update_user()` without authorization checks. This makes it possible for authenticated attackers, with Provider-level (Employee) access and above, to take over any WordPress account \u2014 including Administrator \u2014 by injecting an arbitrary `externalId` value when updating their own provider profile.","date":"2026-04-06"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"5950d750872d8692757238f2fed182a374eba2a0c17805557d741f643a82458b","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 9.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-2931","name":"Amelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-2931","description":"The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with customer-level permissions or above to change user passwords and potentially take over administrator accounts. The vulnerability is in the pro plugin, which has the same slug.","date":"0000-00-00"},{"id":"a7e27b559d871443c59501a7228644a835d0678a","name":"Amelia Booking 8.3 - 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/amelia-booking-912-authenticated-customer-insecure-direct-object-reference-to-arbitrary-user-password-change","description":"The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions 8.3 to 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with customer-level permissions or above to change user passwords and potentially take over administrator accounts. The vulnerability is in the pro plugin, which has the same slug.","date":"2026-03-25"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"c83801e82e6a10ec4839ae0f2740138eb5ddeb018e40fb40bc49ec3c7031efd2","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 1.2.37","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.37","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-49282","name":"CVE-2023-49282","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-49282","description":"[en] msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at vendor\/microsoft\/microsoft-graph\/tests\/GetPhpInfo.php.  The phpInfo function exposes system information. The vulnerability affects the GetPhpInfo.php script of the PHP SDK which contains a call to the phpinfo() function. This vulnerability requires a misconfiguration of the server to be present so it can be exploited. For example, making the PHP application\u2019s \/vendor directory web accessible. The combination of the vulnerability and the server misconfiguration would allow an attacker to craft an HTTP request that executes the phpinfo() method. The attacker would then be able to get access to system information like configuration, modules, and environment variables and later on use the compromised secrets to access additional data. This problem has been patched in versions 1.109.1 and 2.0.0-RC5. If an immediate deployment with the updated vendor package is not available, you can perform the following temporary workarounds: delete the `vendor\/microsoft\/microsoft-graph\/tests\/GetPhpInfo.php` file, remove access to the `\/vendor` directory, or disable the phpinfo function.","date":"2023-12-05"},{"id":"c0548e4a897bb1aedb26cdf5bbc76c026f77d342","name":"Amelia 1.2.18 - 1.2.36 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/amelia-1218-1236-unauthenticated-sensitive-information-exposure","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 1.2.18 to 1.2.36 via the 'phpinfo' function. This makes it possible for unauthenticated attackers to extract sensitive data including server and environment configurations.","date":"2025-11-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"l","score":"5.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}]}},{"uuid":"35c8a5ec36d11ac8189a3d17a27c6c7941e7006794684fff05ad52558fb0fd3b","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-40789","name":"CVE-2026-40789","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-40789","description":"[en] Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.","date":"2026-06-15"},{"id":"8a1621aacda072082a5e4b1f8d4dd5e62a3b21b9","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 2.2 - Unauthenticated Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-22-unauthenticated-information-exposure","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2026-04-23"},{"id":"EUVD-2026-36992","name":"EUVD-2026-36992","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-36992","description":"Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.","date":"2026-06-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-201","name":"Insertion of Sensitive Information Into Sent Data","description":"The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"813c37ee4441ca13dfc6f0cdd320e05b51cfe3397bf62d4846842df72d8a210b","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-6449","name":"CVE-2026-6449","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-6449","description":"[en] The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting' status. This makes it possible for unauthenticated attackers to approve any booking that is in 'waiting' status by sending a crafted request to the publicly-accessible admin-ajax endpoint.","date":"2026-05-02"},{"id":"3c25f3e6f0ca71e5a0227b53412ce7ceadfff31a","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 2.2.1 - Unauthenticated Authorization Bypass via Remote Approval Endpoint","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-212-unauthenticated-authorization-bypass-via-remote-approval-endpoint","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.2.1. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting' status. This makes it possible for unauthenticated attackers to approve any booking that is in 'waiting' status by sending a crafted request to the publicly-accessible admin-ajax endpoint.","date":"2026-05-01"},{"id":"EUVD-2026-26758","name":"EUVD-2026-26758","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-26758","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting' status. This makes it possible for unauthenticated attackers to approve any booking that is in 'waiting' status by sending a crafted request to the publicly-accessible admin-ajax endpoint.","date":"2026-05-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-285","name":"Improper Authorization","description":"The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"563ee8edb8d9d26ceb53a1065bc730bbcdc77ac626a6e26442049781e21b7527","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-40795","name":"CVE-2026-40795","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-40795","description":"[en] Subscriber Broken Access Control in Amelia <= 2.2 versions.","date":"2026-06-15"},{"id":"f3dc212e296d7bf66cab21eaa517ac03570d785f","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 2.2 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-22-missing-authorization","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.","date":"2026-04-28"},{"id":"EUVD-2026-36998","name":"EUVD-2026-36998","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-36998","description":"Subscriber Broken Access Control in Amelia <= 2.2 versions.","date":"2026-06-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"0d97601ba5c2828ec721bfcefbc87d3c4f8de6566663f9c37995d80bceb97776","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-48889","name":"CVE-2026-48889","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-48889","description":"[en] Subscriber Privilege Escalation in Amelia <= 2.3 versions.","date":"2026-06-15"},{"id":"cbf467ae967cf20e0c97287910a990ce226a9528","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 2.3 - Authenticated (Subscriber+) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-23-authenticated-subscriber-privilege-escalation","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.","date":"2026-06-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-266","name":"Incorrect Privilege Assignment","description":"A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"4a588d9c9416f96a9e272dcc00506c0217be51b27025f18b49e12758d4165828","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-57702","name":"CVE-2026-57702","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-57702","description":"[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n\/a through <= 2.4.2.","date":"2026-07-13"},{"id":"EUVD-2026-43359","name":"EUVD-2026-43359","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-43359","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n\/a through <= 2.4.2.","date":"2026-07-13"},{"id":"dc66fcfbbc313ad7ef01902444199393a9fdac72","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 2.4.2 - Unauthenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-242-unauthenticated-sql-injection","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-07-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:N\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"h","i":"n","a":"l","score":"9.3","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:N\/A:L","score":"9.3","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"high","i":"none","a":"low","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"16c0b78219c31a16cb8a0ee96aff99a09d416f00331b2b85459a895e949b6a4c","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-14782","name":"CVE-2026-14782","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-14782","description":"[en] The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with wpamelia-manager role, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-07-16"},{"id":"2edc9bf4d139c3f3ddee21ac317a53fe1ea39f55","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-243-authenticated-custom-sql-injection-via-customer-import","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with wpamelia-manager role, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-07-16"},{"id":"EUVD-2026-45051","name":"EUVD-2026-45051","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-45051","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with wpamelia-manager role, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-07-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"4.9","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"4.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c26ffe1d997d95401b5c73e1cbeeb19139b95380e3f15c31d4bc49f437795508","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-14214","name":"CVE-2026-14214","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-14214","description":"[en] The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.","date":"2026-08-01"},{"id":"6a8c64f197d43fdc83ad2c8f6ff1c43a4a8ffcaa","name":"Booking for Appointments and Events Calendar \u2013 Amelia < 2.4.4 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-244-missing-authorization","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 2.4.4. This makes it possible for authenticated attackers, with custom role-level access and above, to perform an unauthorized action.","date":"2026-08-01"}],"impact":{"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4488e670aa1f4527bb35d2e1673f3226c4cf6c9f1b4aad0a78b6a5cb6f5829e7","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 9.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-14211","name":"CVE-2026-14211","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-14211","description":"[en] The Booking for Appointments and Events Calendar  WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers.","date":"2026-08-10"},{"id":"145107fb93ae7548bcd45969b74198575855f36b","name":"Amelia Pro <= 9.6 - Insecure Direct Object Reference to Authenticated (Provider+) Customer Data Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/amelia-pro-96-insecure-direct-object-reference-to-authenticated-provider-customer-data-disclosure","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.6 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Custom-level access and above, to retrieve arbitrary customer data.","date":"2026-08-14"}],"impact":{"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"0a48cd39bd37f5b656600e2d81f8c0bd3e451a56fc927eaaf0cdfe78a3c6b312","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-14213","name":"CVE-2026-14213","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-14213","description":"[en] The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.","date":"2026-08-13"},{"id":"41bca6b43f0f842b4514e9913d6e74914485f390","name":"Booking for Appointments and Events Calendar \u2013 Amelia < 2.4.6 - Authenticated (Custom role+) Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-246-authenticated-custom-role-information-exposure","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 2.4.6. This makes it possible for authenticated attackers, with custom role-level access and above, to extract sensitive user or configuration data.","date":"2026-08-07"}],"impact":{"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8a83477ff6236928f629143e31226e1518c5e6cc1acf42d17e437f5d757c2878","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-14216","name":"CVE-2026-14216","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-14216","description":"[en] The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.","date":"2026-08-26"},{"id":"65529172c7511e287d525997e5fad337d8482134","name":"Booking for Appointments and Events Calendar \u2013 Amelia < 2.4.7 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-247-missing-authorization","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 2.4.7 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-09-01"}],"impact":{"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5f550b549958ba1f21944b0a396864d94738c84a85258159fc4c57d66cbbc8e1","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 9.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-14212","name":"CVE-2026-14212","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-14212","description":"[en] The Booking for Appointments and Events Calendar  WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password and take over their account.","date":"2026-08-26"},{"id":"3cb84623b7f27eefe077a4a95e3d50c2238e41e6","name":"Booking for Appointments and Events Calendar \u2013 Amelia 9.0 - 9.7 - Authenticated (Provider+) Arbitrary Provider Password Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-90-97-authenticated-provider-arbitrary-provider-password-update","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 9.0 to 9.7 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Provider-level access and above, to reset the passwords of other provider accounts.","date":"2026-09-01"}],"impact":{"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3b45d36ece3937f788f6406a2679074f1fc1d6f1e09336aa20f45cedbe9bb2ff","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-6286","name":"CVE-2026-6286","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-6286","description":"[en] The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication bypass where the AddBookingCommand explicitly skips nonce verification (Command.php line 186), allowing unauthenticated users to submit booking data. While the plugin applies sanitize_text_field() to customer firstName and lastName fields (BookingApplicationService.php lines 302-308), this function only removes HTML tags and preserves special characters including double quotes. The vulnerability manifests in the administrative Calendar view where a FullCalendar eventContent callback interpolates customer names directly into JavaScript template literals (redesign\/dist\/index.js line 199) and renders them via innerHTML without proper HTML entity encoding. Because double quotes are preserved, an attacker can inject payloads like '\" onmouseover=\"alert(document.cookie)\"' to break out of the title attribute and inject malicious event handlers. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute when an administrator accesses the Calendar page and hovers over the malicious appointment.","date":"2026-08-28"},{"id":"36e1ba29f2579a24cd264eafefd44dc35be0cf88","name":"Booking for Appointments and Events Calendar <= 2.2 - Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-22-unauthenticated-stored-cross-site-scripting-via-customer-name-fields-in-booking-submission","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication bypass where the AddBookingCommand explicitly skips nonce verification (Command.php line 186), allowing unauthenticated users to submit booking data. While the plugin applies sanitize_text_field() to customer firstName and lastName fields (BookingApplicationService.php lines 302-308), this function only removes HTML tags and preserves special characters including double quotes. The vulnerability manifests in the administrative Calendar view where a FullCalendar eventContent callback interpolates customer names directly into JavaScript template literals (redesign\/dist\/index.js line 199) and renders them via innerHTML without proper HTML entity encoding. Because double quotes are preserved, an attacker can inject payloads like '\" onmouseover=\"alert(document.cookie)\"' to break out of the title attribute and inject malicious event handlers. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute when an administrator accesses the Calendar page and hovers over the malicious appointment.","date":"2026-08-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"963c4f733f1ee7ac28dcd53235ab86bc86a896bd2f36219a268be22f8ca4d8bc","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-77704","name":"CVE-2026-77704","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-77704","description":"[en] The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were left awaiting approval and overwriting another customer's booking status on a shared appointment.","date":"2026-08-29"},{"id":"fc1ea3a26308c6628ecf77e2f3990914058e484a","name":"Booking for Appointments and Events Calendar \u2013 Amelia 1.2.32 - 2.4.8 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-1232-248-missing-authorization","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to unauthorized access in versions 1.2.32 through 2.4.8. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with custom role-level access and above, to perform an unauthorized action.","date":"2026-09-01"}],"impact":{"cwe":[{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d882936483db7833c8547d81a35ddba1f7f00740a93a05cb115ce5cbac2afc60","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 9.6.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.6.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-9055","name":"CVE-2026-9055","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-9055","description":"[en] The Booking for Appointments and Events Calendar \u2013 Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when the 'externalId' parameter is set to 0. This makes it possible for unauthenticated attackers to escalate their privileges to administrator by first elevating to the manager role, then creating a provider entity linked to an administrator user ID and overwriting that administrator's password.","date":"2026-09-02"},{"id":"ce4b6169f26a9164b1cec66c89961017fe779566","name":"Booking for Appointments and Events Calendar \u2013 Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-premium-80-962-unauthenticated-privilege-escalation-to-administrator-via-externalid","description":"The Booking for Appointments and Events Calendar \u2013 Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when the 'externalId' parameter is set to 0. This makes it possible for unauthenticated attackers to escalate their privileges to administrator by first elevating to the manager role, then creating a provider entity linked to an administrator user ID and overwriting that administrator's password.","date":"2026-08-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-269","name":"Improper Privilege Management","description":"The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"9b41178eba4b9824f1d82c30fa6cb7eeec501eec1b178e1caa32c8035bf98c19","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-14215","name":"CVE-2026-14215","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-14215","description":"[en] The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier.","date":"2026-09-02"},{"id":"dfc3152992133ef89453b707cb54cd8c5380ec7a","name":"Booking for Appointments and Events Calendar \u2013 Amelia < 2.4.9 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-249-missing-authorization","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 2.4.9 (exclusive). This makes it possible for unauthenticated attackers to trigger post-booking chains.","date":"2026-09-01"}],"impact":{"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7bdbf59e8f8abf13f7605e2c053940473446058e72140d803651425443c2ffe0","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-62112","name":"CVE-2026-62112","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-62112","description":"[en] Editor SQL Injection in Amelia <= 2.4.9 versions.","date":"2026-09-11"},{"id":"bdefff86456bf73a362d00d4a34da20d15e903d9","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 2.4.9 - Authenticated (Editor+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-249-authenticated-editor-sql-injection","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.4.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-09-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:N\/A:L","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"h","i":"n","a":"l","score":"7.6","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:N\/A:L","score":"7.6","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"changed","c":"high","i":"none","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ddde0bb9702e3ff0b22ceaf16e26733fafb3ea25dc1a299bed95fdc046612dc3","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-10148","name":"CVE-2026-10148","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-10148","description":"[en] The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of classes. This makes it possible for authenticated attackers, with Contributor-level access and above who can use Elementor, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 2.4.8.","date":"2026-09-12"},{"id":"eb5afd28783ce03d66662ef8949cc55b618fc2a7","name":"Booking for Appointments and Events Calendar \u2013 Amelia <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-249-authenticated-contributor-stored-cross-site-scripting-via-load-manually-parameter","description":"The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of classes. This makes it possible for authenticated attackers, with Contributor-level access and above who can use Elementor, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 2.4.8.","date":"2026-09-01"},{"id":"EUVD-2026-76874","name":"EUVD-2026-76874","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-76874","description":"The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of classes. This makes it possible for authenticated attackers, with Contributor-level access and above who can use Elementor, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 2.4.8.","date":"2026-09-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"91cc6eefdd6ddfc0412681d830fba24969ea15e030731db3a8a9c2370ff2b741","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-77705","name":"CVE-2026-77705","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-77705","description":"[en] The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.","date":"2026-09-12"},{"id":"EUVD-2026-76812","name":"EUVD-2026-76812","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-76812","description":"The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.","date":"2026-09-12"},{"id":"eb2095d29000766765fef7f33a9ccbb8ee675342","name":"Booking for Appointments and Events Calendar \u2013 Amelia < 2.4.10 - Authenticated (Custom Role+) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-2410-authenticated-custom-role-privilege-escalation","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 2.4.10. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for authenticated attackers, with custom role-level access and above, to elevate their privileges beyond those intended for their role.","date":"2026-09-17"}],"impact":{"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":null,"impact":null},"epss":"0.001"}},{"uuid":"d460d0a4708e1b4bdeb99b6a6af071dd6854ce85004ca256ff1762618d90ef6b","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] >= 9.0 - < 9.8.1","description":null,"operator":{"min_version":"9.0","min_operator":"ge","max_version":"9.8.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-77689","name":"CVE-2026-77689","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-77689","description":"[en] The Booking for Appointments and Events Calendar  WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an unauthenticated attacker obtain confirmed, fully paid appointments and events without any payment being collected.","date":"2026-09-12"},{"id":"EUVD-2026-76813","name":"EUVD-2026-76813","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-76813","description":"The Booking for Appointments and Events Calendar  WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an unauthenticated attacker obtain confirmed, fully paid appointments and events without any payment being collected.","date":"2026-09-12"},{"id":"02451f1a06bfd4a4fc53f5618d579dfba82503f5","name":"Booking for Appointments and Events Calendar \u2013 Amelia 9.0 - 9.8.0 - Unauthenticated Payment Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-90-980-unauthenticated-payment-bypass","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to Payment Bypass in versions 9.0 to 9.8.0. This makes it possible for unauthenticated attackers to bypass payments for appointments.","date":"2026-09-14"}],"impact":{"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":null,"impact":null},"epss":"0.002"}},{"uuid":"a861972dc0bbfd6c665853bd768f11b4e6478c5d5f6de79cd505f2dbe2cf3b8e","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-16582","name":"CVE-2026-16582","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-16582","description":"[en] The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This is due to the plugin accepting a client-supplied package-redemption identifier as proof of payment without validating it. This makes it possible for unauthenticated attackers to create approved appointment bookings without completing payment","date":"2026-09-17"},{"id":"20542c6b5d1541f255e234011c79b16c95c782d5","name":"Booking for Appointments and Events Calendar - Amelia <= 2.4.5 - Missing Authorization to Unauthenticated Payment Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-245-missing-authorization-to-unauthenticated-payment-bypass","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This is due to the plugin accepting a client-supplied package-redemption identifier as proof of payment without validating it. This makes it possible for unauthenticated attackers to create approved appointment bookings without completing payment","date":"2026-09-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}},{"uuid":"7148e65cbab996f0b56fa70f9255f5307229fe063dc2f077f705083e8acfe967","name":"Booking for Appointments and Events Calendar &#8211; Amelia [ameliabooking] < 2.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-14311","name":"CVE-2026-14311","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-14311","description":"[en] The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on \/users\/customers\/<id> endpoint  in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with wpamelia-provider role, to view and modify arbitrary customers, including password reset. Takeover of WordPress user accounts, with the roles up to Editor, is also possible if that user had made an Amelia booking. This vulnerability affects only the Premium version of the plugin, where the Employee Panel is present.","date":"2026-09-17"},{"id":"39d2643a9cf70406e7d6e6aacd47ca35c8f8e07e","name":"Booking for Appointments and Events Calendar \u2013 Amelia (Premium) <= 2.4.4 - Authenticated (Custom+) Missing Authorization to Limited Account Takeover","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ameliabooking\/booking-for-appointments-and-events-calendar-amelia-premium-244-authenticated-custom-missing-authorization-to-limited-account-takeover","description":"The Booking for Appointments and Events Calendar \u2013 Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on \/users\/customers\/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with wpamelia-provider role, to view and modify arbitrary customers, including password reset. Takeover of WordPress user accounts, with the roles up to Editor, is also possible if that user had made an Amelia booking. This vulnerability affects only the Premium version of the plugin, where the Employee Panel is present.","date":"2026-09-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789709532"}