Extension WordPress

Vulnérabilités Booking for Appointments and Events Calendar – Amelia, page 2

Cette page rassemble les failles publiées pour Booking for Appointments and Events Calendar – Amelia, leurs plages de versions affectées et les correctifs signalés dans la base locale.

33Vulnérabilités
0Critiques
33Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Booking for Appointments and Events Calendar – Amelia

33 fiches

CVE-2024-1484 Moyenne · 6,1
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 1.0.98 – Reflected Cross-Site Scripting

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the date parameters in all versions up to, and including, 1.0.98 due to insufficient input sanitization and output escaping.…

Versions affectées

*-1.0.98

Correctif

1.0.99

Publication

29/02/2024

CVE-2023-6808 Moyenne · 6,4
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 1.0.93 – Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.93 due to insufficient input sanitization and output escaping…

Versions affectées

*-1.0.93

Correctif

1.0.94

Publication

18/01/2024

CVE-2023-50860 Moyenne · 6,4
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 1.0.85 – Stored Cross-Site Scripting via Shortcode

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.85 due to insufficient input sanitization and output escaping…

Versions affectées

*-1.0.85

Correctif

1.0.86

Publication

22/12/2023

CVE-2023-29427 Moyenne · 6,1
Booking for Appointments and Events Calendar – Amelia

Amelia <= 1.0.75 – Unauthenticated Reflected Cross-Site Scripting via 'code'

The Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'code' parameter in versions up to, and including, 1.0.75 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-1.0.75

Correctif

1.0.76

Publication

06/04/2023

CVE-2022-0837 Moyenne · 6,4
Booking for Appointments and Events Calendar – Amelia

Appointment and Event Booking Calendar for WordPress – Amelia <= 1.0.47 – Information Disclosure and SMS Spam

The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email,…

Versions affectées

[*, 1.0.48)

Correctif

1.0.48

Publication

14/03/2022

CVE-2022-0825 Moyenne · 5,4
Booking for Appointments and Events Calendar – Amelia

Appointment and Event Booking Calendar for WordPress – Amelia < 1.0.49 – Arbitrary Booking Update and Sensitive Data Exposure

The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone…

Versions affectées

[*, 1.0.49)

Correctif

1.0.49

Publication

14/03/2022

CVE-2022-0834 Élevée · 7,2
Booking for Appointments and Events Calendar – Amelia

Amelia <= 1.0.46 – Stored Cross Site Scripting via lastName

The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever…

Versions affectées

*-1.0.46

Correctif

1.0.47

Publication

02/03/2022

CVE-2022-0720 Moyenne · 5,4
Booking for Appointments and Events Calendar – Amelia

Appointment and Event Booking Calendar for WordPress – Amelia < 1.0.47 – Arbitrary Booking Update and Sensitive Data Exposure

The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number…

Versions affectées

[*, 1.0.47)

Correctif

1.0.47

Publication

01/03/2022

CVE-2022-0687 Élevée · 8,8
Booking for Appointments and Events Calendar – Amelia

Appointment and Event Booking Calendar – Amelia < 1.0.47 – Arbitrary File Upload

The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users…

Versions affectées

[*, 1.0.47)

Correctif

1.0.47

Publication

23/02/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités