CVE-2022-0834
Estado: ModificadaMedia (5.4)—
The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user accesses the booking calendar with the date the attacker has injected the malicious payload into. This affects versions up to and including 1.0.46.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.54%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
- CWE-79
Referencias
- https://www.wordfence.com/threat-intel/vulnerabilities/id/73f12f22-c0a4-4010-9634-ce7308254028?source=cve
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0834
- https://www.wordfence.com/threat-intel/vulnerabilities/id/73f12f22-c0a4-4010-9634-ce7308254028?source=cve
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0834
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-0834",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-0834",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-11-20T15:39:55.643999Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@wordfence.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "security@wordfence.com",
"affectedData": [
{
"vendor": "ameliabooking",
"product": "Booking for Appointments and Events Calendar – Amelia",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "1.0.46"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2022-03-23T20:15:10.367",
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/73f12f22-c0a4-4010-9634-ce7308254028?source=cve",
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0834",
"tags": [
"Third Party Advisory"
],
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/73f12f22-c0a4-4010-9634-ce7308254028?source=cve",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0834",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@wordfence.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Secondary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user accesses the booking calendar with the date the attacker has injected the malicious payload into. This affects versions up to and including 1.0.46."
},
{
"lang": "es",
"value": "El plugin Amelia de WordPress es vulnerable a un ataque de tipo Cross-Site Scripting debido a un insuficiente escape y saneo del parámetro lastName encontrado en el archivo ~/src/Application/Controller/User/Customer/AddCustomerController.php que permite a atacantes inyectar scripts web arbitrarios en una página que es ejecutada cada vez que un usuario accede al calendario de reservas con la fecha en la que el atacante ha inyectado una carga útil maliciosa. Esto afecta a versiones hasta la 1.0.46 incluyéndola"
}
],
"lastModified": "2026-06-17T04:21:20.300",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wpamelia:amelia:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "D64E1EB1-C0BC-4BF6-8FB4-76B361F9972C",
"versionEndIncluding": "1.0.46"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@wordfence.com"
}