« Volver al listado

Ameliabooking

Ameliabooking Amelia: vulnerabilidades y CVE

Ameliabooking Amelia tiene 17 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE17
Últimos 12 meses16
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-14311Media (5.4)0.17%—17 sept 2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in…
CVE-2026-62112Alta (7.6)0.38%—11 sept 2026
Editor SQL Injection in Amelia <= 2.4.9 versions.
CVE-2026-9055Crítica (9.8)0.51%—2 sept 2026
The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled…
CVE-2026-6286Alta (7.2)0.62%—28 ago 2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication…
CVE-2026-14782Media (4.9)0.41%—16 jul 2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user…
CVE-2026-48889Alta (8.8)0.42%—15 jun 2026
Subscriber Privilege Escalation in Amelia <= 2.3 versions.
CVE-2026-40789Alta (7.5)0.42%—15 jun 2026
Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.
CVE-2026-6449Media (5.3)0.42%—2 may 2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in…
CVE-2026-39487Alta (7.6)0.38%—8 abr 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.1.1.
CVE-2026-5465Alta (8.8)0.56%—7 abr 2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the…
CVE-2026-4668Media (6.5)0.41%—1 abr 2026
The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and including, 2.1.2. This…
CVE-2026-2931Alta (8.8)0.55%—26 mar 2026
The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user…
CVE-2026-24963Alta (7.2)0.32%—5 mar 2026
Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issue affects Amelia: from n/a through <= 1.2.38.
CVE-2026-24967Media (5.3)0.26%—3 feb 2026
Missing Authorization vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <= 1.2.38.
CVE-2025-14720Media (5.3)0.32%—9 ene 2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38.…
CVE-2025-12482Alta (7.5)0.32%—16 nov 2025
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the…
CVE-2025-26965Media (5.3)0.44%—25 feb 2025
Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <=…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services7
  2. T1005 Data from Local System4
  3. T1190 Exploit Public-Facing Application4
  4. T1068 Exploitation for Privilege Escalation3
  5. T1098.002 Additional Email Delegate Permissions2
  6. T1059.007 JavaScript1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Ameliabooking