Extension WordPress

Vulnérabilités Booking for Appointments and Events Calendar – Amelia

Cette page rassemble les failles publiées pour Booking for Appointments and Events Calendar – Amelia, leurs plages de versions affectées et les correctifs signalés dans la base locale.

33Vulnérabilités
0Critiques
33Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Booking for Appointments and Events Calendar – Amelia

33 fiches

CVE-2026-14782 Moyenne · 4,9
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 2.4.3 – Authenticated (Custom+) SQL Injection via Customer Import

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-2.4.3

Correctif

2.4.4

Publication

16/07/2026

CVE-2026-57702 Élevée · 7,5
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 2.4.2 – Unauthenticated SQL Injection

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

Versions affectées

*-2.4.2

Correctif

2.4.3

Publication

08/07/2026

CVE-2026-48889 Élevée · 8,8
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 2.3 – Authenticated (Subscriber+) Privilege Escalation

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

Versions affectées

*-2.3

Correctif

2.4

Publication

02/06/2026

CVE-2026-6449 Moyenne · 5,3
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 2.2.1 – Unauthenticated Authorization Bypass via Remote Approval Endpoint

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.2.1. This is due to a logical short-circuit flaw in authorization logic that causes…

Versions affectées

*-2.2.1

Correctif

2.3

Publication

01/05/2026

CVE-2026-40795 Moyenne · 4,3
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 2.2 – Missing Authorization

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2. This makes it possible for…

Versions affectées

*-2.2

Correctif

2.2.1

Publication

28/04/2026

CVE-2026-40789 Moyenne · 5,3
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 2.2 – Unauthenticated Information Exposure

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to extract sensitive user or…

Versions affectées

*-2.2

Correctif

2.2.1

Publication

23/04/2026

CVE-2026-5465 Élevée · 8,8
Booking for Appointments and Events Calendar – Amelia

Amelia <= 2.1.3 – Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the `UpdateProviderCommandHandler` failing to validate changes to…

Versions affectées

*-2.1.3

Correctif

2.2

Publication

06/04/2026

CVE-2026-2931 Élevée · 8,8
Booking for Appointments and Events Calendar – Amelia

Amelia Booking 8.3 – 9.1.2 – Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change

The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions 8.3 to 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources.…

Versions affectées

8.3-9.1.2

Correctif

9.2

Publication

25/03/2026

CVE-2026-24963 Élevée · 8,8
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 1.2.38 – Authenticated (Employee+) Privilege Escalation

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.38. This makes it possible for authenticated attackers, with employee-level access and above, to…

Versions affectées

*-1.2.38

Correctif

2.0

Publication

04/03/2026

CVE-2025-14720 Moyenne · 5,3
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 1.2.38 – Missing Authorization to Unauthenticated Multiple AJAX Actions

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible…

Versions affectées

*-1.2.38

Correctif

2.0.0

Publication

08/01/2026

CVE-2023-49282 Moyenne · 5,3
Booking for Appointments and Events Calendar – Amelia

Amelia 1.2.18 – 1.2.36 – Unauthenticated Sensitive Information Exposure

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 1.2.18 to 1.2.36 via the 'phpinfo' function. This makes it possible for unauthenticated attackers to extract sensitive data…

Versions affectées

1.2.18-1.2.36

Correctif

1.2.37

Publication

18/11/2025

CVE-2025-12482 Élevée · 7,5
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 1.2.35 – Unauthenticated SQL Injection via search

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-1.2.35

Correctif

1.2.36

Publication

15/11/2025

CVE-2025-2578 Moyenne · 5,3
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 1.2.19 – Unauthenticated Full Path Disclosure

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to…

Versions affectées

*-1.2.19

Correctif

1.2.20

Publication

27/03/2025

CVE-2024-6332 Moyenne · 6,5
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia Premium <= 7.7 and Lite <= 1.2.4 – Missing Authorization to Sensitive Information Exposure

The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the 'ameliaButtonCommand' function in all versions up to, and…

Versions affectées

*-1.2.4

Correctif

1.2.5

Publication

04/09/2024

CVE-2024-6552 Moyenne · 5,3
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 1.2 – Unauthenticated Full Path Disclosure

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on…

Versions affectées

*-1.2

Correctif

1.2.1

Publication

07/08/2024

CVE-2024-6225 Moyenne · 4,4
Booking for Appointments and Events Calendar – Amelia

Amelia <= 1.1.5 & Amelia (Pro) <= 7.5.1 – Authenticated (Admin+) Stored Cross-Site Scripting

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.5 (and 7.5.1 for the Pro version) due to insufficient…

Versions affectées

*-1.1.5

Correctif

1.1.6

Publication

20/06/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités