Ameliabooking
Ameliabooking Amelia: vulnerabilities and CVEs
Ameliabooking Amelia has 17 published vulnerabilities, 16 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs17
Last 12 months16
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14311 | Medium (5.4) | 0.17% | — | Sep 17, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in… |
| CVE-2026-62112 | High (7.6) | 0.38% | — | Sep 11, 2026 | Editor SQL Injection in Amelia <= 2.4.9 versions. |
| CVE-2026-9055 | Critical (9.8) | 0.51% | — | Sep 2, 2026 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled… |
| CVE-2026-6286 | High (7.2) | 0.62% | — | Aug 28, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication… |
| CVE-2026-14782 | Medium (4.9) | 0.41% | — | Jul 16, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user… |
| CVE-2026-48889 | High (8.8) | 0.42% | — | Jun 15, 2026 | Subscriber Privilege Escalation in Amelia <= 2.3 versions. |
| CVE-2026-40789 | High (7.5) | 0.42% | — | Jun 15, 2026 | Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions. |
| CVE-2026-6449 | Medium (5.3) | 0.42% | — | May 2, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in… |
| CVE-2026-39487 | High (7.6) | 0.38% | — | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.1.1. |
| CVE-2026-5465 | High (8.8) | 0.56% | — | Apr 7, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the… |
| CVE-2026-4668 | Medium (6.5) | 0.41% | — | Apr 1, 2026 | The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and including, 2.1.2. This… |
| CVE-2026-2931 | High (8.8) | 0.55% | — | Mar 26, 2026 | The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user… |
| CVE-2026-24963 | High (7.2) | 0.32% | — | Mar 5, 2026 | Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issue affects Amelia: from n/a through <= 1.2.38. |
| CVE-2026-24967 | Medium (5.3) | 0.26% | — | Feb 3, 2026 | Missing Authorization vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <= 1.2.38. |
| CVE-2025-14720 | Medium (5.3) | 0.32% | — | Jan 9, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38.… |
| CVE-2025-12482 | High (7.5) | 0.32% | — | Nov 16, 2025 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the… |
| CVE-2025-26965 | Medium (5.3) | 0.44% | — | Feb 25, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <=… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.