← WordPress Vulnerabilities
WordPress security by component

Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia is a WordPress component with 21 published CVE records in this archive. The latest tracked vulnerability was published Jul 16, 2026; the highest CVE/CNA score is 9.3.

Plugin slug: ameliabooking

CVE-2026-14782: Booking for Appointments and Events Calendar – Amelia: SQL injection

Booking for Appointments and Events Calendar – Amelia is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 2.4.3.

PublishedJul 16, 2026
Known safe version> 2.4.3
Safe version
Jul 16, 2026 CVE-2026-14782
Booking for Appointments and Events Calendar – Amelia: SQL injection
Booking for Appointments and Events Calendar – Amelia is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 2.4.3.
> 2.4.3
CVE4.9
NVDPending
Jul 13, 2026 CVE-2026-57702
Amelia: SQL injection
Amelia is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 2.4.2.
2.4.3
CVE9.3
NVDPending
Jun 15, 2026 CVE-2026-48889
Amelia: Privilege escalation or authentication bypass
Amelia is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 2.3.
2.4
CVE8.8
NVDPending
Jun 15, 2026 CVE-2026-40795
Amelia: A security weakness
Amelia is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.2.
2.2.1
CVE6.5
NVDPending
Jun 15, 2026 CVE-2026-40789
Amelia: A security weakness
Amelia is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.2.
2.2.1
CVE7.5
NVDPending
May 02, 2026 CVE-2026-6449
Booking for Appointments and Events Calendar – Amelia: A security weakness
Booking for Appointments and Events Calendar – Amelia is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.1.2.
> 2.1.2
CVE5.3
NVDPending
Apr 08, 2026 CVE-2026-39487
Amelia: SQL injection
Amelia is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 2.1.1.
2.1.2
CVE7.6
NVDPending
Apr 07, 2026 CVE-2026-5465
Booking for Appointments and Events Calendar – Amelia: A security weakness
Booking for Appointments and Events Calendar – Amelia is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.1.3.
> 2.1.3
CVE8.8
NVDPending
Apr 01, 2026 CVE-2026-4668
Booking for Appointments and Events Calendar – Amelia: SQL injection
Booking for Appointments and Events Calendar – Amelia is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 2.1.2.
> 2.1.2
CVE6.5
NVDPending
Mar 26, 2026 CVE-2026-2931
Booking for Appointments and Events Calendar – Amelia: A security weakness
Booking for Appointments and Events Calendar – Amelia is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 9.1.2.
> 9.1.2
CVE8.8
NVDPending
Mar 05, 2026 CVE-2026-24963
Amelia: Privilege escalation or authentication bypass
Amelia is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.2
NVDPending
Feb 03, 2026 CVE-2026-24967
Amelia: A security weakness
Amelia is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Mar 28, 2025 CVE-2025-2578
Booking for Appointments and Events Calendar – Amelia: A security weakness
Booking for Appointments and Events Calendar – Amelia is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Feb 25, 2025 CVE-2025-26965
Amelia: A security weakness
Amelia is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 05, 2024 CVE-2024-6332
Ameliabooking: A security weakness
Ameliabooking is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Aug 08, 2024 CVE-2024-6552
Booking for Appointments and Events Calendar – Amelia: A security weakness
Booking for Appointments and Events Calendar – Amelia is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jun 10, 2024 CVE-2024-22298
Amelia: A security weakness
Amelia is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD9.8
Apr 15, 2024 CVE-2024-31425
Amelia: Cross-site request forgery
Amelia is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Dec 28, 2023 CVE-2023-50860
Booking for Appointments and Events Calendar – Amelia: Cross-site scripting
Booking for Appointments and Events Calendar – Amelia is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 26, 2023 CVE-2023-29427
Ameliabooking: Cross-site scripting
Ameliabooking is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
May 10, 2023 CVE-2023-27918
Ameliabooking: Cross-site scripting
Ameliabooking is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1