Plugin Vulnerability Hub
Plugin 22 known issues Latest disclosed Mar 25, 2026

Booking for Appointments and Events Calendar – Amelia Vulnerabilities

Review known vulnerability records for the WordPress plugin Booking for Appointments and Events Calendar – Amelia (`ameliabooking`), including severity, CVE references, affected versions, and patch status.

Known Records
22
High or Critical
5
Linked CVEs
22
Last Updated
Mar 25, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Booking for Appointments and Events Calendar – Amelia so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
22 records include a published patch path.
Severity Mix
0 critical and 5 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Booking for Appointments and Events Calendar – Amelia

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-2931
Amelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change

The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes i...

Published
Mar 25, 2026
Patched Release
9.2
Affected Versions
Versions up to 9.1.2
Next Step
Update to 9.2 or newer if supported.
Plugin High Patched: Yes CVE-2026-24963
Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Authenticated (Employee+) Privilege Escalation

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.38. This makes it possible for authenticated attackers, with employee-level access and above, to elevate their privileges...

Published
Mar 04, 2026
Patched Release
2.0
Affected Versions
Versions up to 1.2.38
Next Step
Update to 2.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24967
Amelia <= 1.2.38 - Missing Authorization

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to perform an una...

Published
Jan 11, 2026
Patched Release
2.0
Affected Versions
Versions up to 1.2.38
Next Step
Update to 2.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-14720
Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark...

Published
Jan 08, 2026
Patched Release
2.0.0
Affected Versions
Versions up to 1.2.38
Next Step
Update to 2.0.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-49282
Amelia 1.2.18 - 1.2.36 - Unauthenticated Sensitive Information Exposure

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 1.2.18 to 1.2.36 via the 'phpinfo' function. This makes it possible for unauthenticated attackers to extract sensitive data including server...

Published
Nov 18, 2025
Patched Release
1.2.37
Affected Versions
1.2.18 through 1.2.36
Next Step
Update to 1.2.37 or newer if supported.
Plugin High Patched: Yes CVE-2025-12482
Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via search

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...

Published
Nov 15, 2025
Patched Release
1.2.36
Affected Versions
Versions up to 1.2.35
Next Step
Update to 1.2.36 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-2578
Booking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure

The Booking for Appointments and Events Calendar &#8211; Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to retrieve the full pa...

Published
Mar 27, 2025
Patched Release
1.2.20
Affected Versions
Versions up to 1.2.19
Next Step
Update to 1.2.20 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-26965
Amelia <= 1.2.16 - Unauthenticated Insecure Direct Object Reference

The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.16 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers t...

Published
Feb 23, 2025
Patched Release
1.2.17
Affected Versions
Versions up to 1.2.16
Next Step
Update to 1.2.17 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-6552
Booking for Appointments and Events Calendar – Amelia <= 1.2 - Unauthenticated Full Path Disclosure

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for...

Published
Aug 07, 2024
Patched Release
1.2.1
Affected Versions
Versions up to 1.2
Next Step
Update to 1.2.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-31425
Amelia <= 1.0.95 - Cross-Site Request Forgery

The Amelia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.95. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a f...

Published
Apr 10, 2024
Patched Release
1.0.96
Affected Versions
Versions up to 1.0.95
Next Step
Update to 1.0.96 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-1484
Booking for Appointments and Events Calendar – Amelia <= 1.0.98 - Reflected Cross-Site Scripting

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the date parameters in all versions up to, and including, 1.0.98 due to insufficient input sanitization and output escaping. This makes it possible f...

Published
Feb 29, 2024
Patched Release
1.0.99
Affected Versions
Versions up to 1.0.98
Next Step
Update to 1.0.99 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-6808
Booking for Appointments and Events Calendar – Amelia <= 1.0.93 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.93 due to insufficient input sanitization and output escaping on user supplied attri...

Published
Jan 18, 2024
Patched Release
1.0.94
Affected Versions
Versions up to 1.0.93
Next Step
Update to 1.0.94 or newer if supported.