HomeWordPress vulnerabilitiesBooking for Appointments and Events Calendar
Booking for Appointments and Events Calendar vulnerabilities
Booking for Appointments and Events Calendar has 27 known vulnerabilities in this database. The most recent published record is dated 17 Sep 2026.
- Known vulnerabilities
- 27
- Active installs
- 90,000+
- Latest version
- 2.4.11
- Last updated
- 24 Sep 2026
- Most recent
- 17 Sep 2026
No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Broken access control CVE-2026-14311 | Medium 5.4 | Up to 2.4.4 | Fixed in a later version (latest 2.4.11) | 17 Sep 2026 |
| Broken access control CVE-2026-16582 | Medium 5.3 | Up to 2.4.5 | Fixed in a later version (latest 2.4.11) | 17 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-10148 | Medium 6.4 | Up to 2.4.9 | Fixed in a later version (latest 2.4.11) | 12 Sep 2026 |
| Broken access control CVE-2026-77689 | Medium 5.3 | Before 9.8.1 | Fixed in 9.8.1 | 12 Sep 2026 |
| Broken access control CVE-2026-77705 | High 7.2 | Before 2.4.10 | Fixed in 2.4.10 | 12 Sep 2026 |
| Broken access control CVE-2026-14215 | Medium 6.5 | Before 2.4.9 | Fixed in 2.4.9 | 2 Sep 2026 |
| Broken access control CVE-2026-77704 | Low 2.7 | Before 2.4.9 | Fixed in 2.4.9 | 29 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-6286 | High 7.2 | Up to 2.2 | Fixed in a later version (latest 2.4.11) | 28 Aug 2026 |
| Broken access control CVE-2026-14212 | Medium 4.7 | Before 9.8 | Fixed in 9.8 | 26 Aug 2026 |
| Authentication bypass CVE-2026-14216 | Medium 6.5 | Before 2.4.7 | Fixed in 2.4.7 | 26 Aug 2026 |
| Broken access control CVE-2026-14213 | Low 3.7 | Before 2.4.6 | Fixed in 2.4.6 | 13 Aug 2026 |
| Broken access control CVE-2026-14211 | Low 3.8 | Before 9.7 | Fixed in 9.7 | 10 Aug 2026 |
| Authentication bypass CVE-2026-14214 | Low 2.7 | Before 2.4.4 | Fixed in 2.4.4 | 1 Aug 2026 |
| SQL injection CVE-2026-14782 | Medium 4.9 | Up to 2.4.3 | Fixed in a later version (latest 2.4.11) | 16 Jul 2026 |
| Broken access control CVE-2026-6449 | Medium 5.3 | Up to 2.1.2 | Fixed in a later version (latest 2.4.11) | 2 May 2026 |
| Broken access control CVE-2026-5465 | High 8.8 | Up to 2.1.3 | Fixed in a later version (latest 2.4.11) | 7 Apr 2026 |
| SQL injection CVE-2026-4668 | Medium 6.5 | Up to 2.1.2 | Fixed in a later version (latest 2.4.11) | 1 Apr 2026 |
| Broken access control CVE-2026-2931 | High 8.8 | Up to 9.1.2 | No fixed version yet | 26 Mar 2026 |
| Broken access control CVE-2025-14720 | Medium 5.3 | Up to 1.2.38 | Fixed in a later version (latest 2.4.11) | 9 Jan 2026 |
| SQL injection CVE-2025-12482 | High 7.5 | Up to 1.2.35 | Fixed in a later version (latest 2.4.11) | 16 Nov 2025 |
| Sensitive data exposure CVE-2025-2578 | Medium 5.3 | Up to 1.2.19 | Fixed in a later version (latest 2.4.11) | 28 Mar 2025 |
| Broken access control CVE-2024-6332 | Medium 6.5 | Up to 7.7 | No fixed version yet | 5 Sep 2024 |
| Sensitive data exposure CVE-2024-6552 | Medium 5.3 | Up to 1.2 | Fixed in a later version (latest 2.4.11) | 8 Aug 2024 |
| Cross-site scripting (XSS) CVE-2024-6225 | Medium 4.4 | Before 1.1.6 | Fixed in 1.1.6 | 21 Jun 2024 |
| Cross-site scripting (XSS) CVE-2024-1484 | Medium 6.1 | Before 1.0.99 | Fixed in 1.0.99 | 13 Mar 2024 |
| Cross-site scripting (XSS) CVE-2023-6808 | Medium 6.4 | Up to 1.0.93 | Fixed in a later version (latest 2.4.11) | 5 Feb 2024 |
| Cross-site scripting (XSS) CVE-2023-27918 | Medium 6.1 | Before 1.0.76 | Fixed in 1.0.76 | 10 May 2023 |
Read the published descriptions
- CVE-2026-14311, 17 Sep 2026
- The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with wpamelia-provider role, to view and modify arbitrary customers, including password reset. Takeover of WordPress user accounts, with the roles up to Editor, is also possible if that user had made an Amelia booking. This vulnerability affects only the Premium version of the plugin, where the Employee Panel is present. CVE record
- CVE-2026-16582, 17 Sep 2026
- The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This is due to the plugin accepting a client-supplied package-redemption identifier as proof of payment without validating it. This makes it possible for unauthenticated attackers to create approved appointment bookings without completing payment CVE record
- CVE-2026-10148, 12 Sep 2026
- The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of classes. This makes it possible for authenticated attackers, with Contributor-level access and above who can use Elementor, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 2.4.8. CVE record
- CVE-2026-77689, 12 Sep 2026
- The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an unauthenticated attacker obtain confirmed, fully paid appointments and events without any payment being collected. CVE record
- CVE-2026-77705, 12 Sep 2026
- The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over. CVE record
- CVE-2026-14215, 2 Sep 2026
- The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier. CVE record
- CVE-2026-77704, 29 Aug 2026
- The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were left awaiting approval and overwriting another customer's booking status on a shared appointment. CVE record
- CVE-2026-6286, 28 Aug 2026
- The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication bypass where the AddBookingCommand explicitly skips nonce verification (Command.php line 186), allowing unauthenticated users to submit booking data. While the plugin applies sanitize_text_field() to customer firstName and lastName fields (BookingApplicationService.php lines 302-308), this function only removes HTML tags and preserves special characters including double quotes. The vulnerability manifests in the administrative Calendar view where a FullCalendar eventContent callback interpolates customer names directly into JavaScript template literals (redesign/dist/index.js line 199) and renders them via innerHTML without proper HTML entity encoding. Because double quotes are preserved, an attacker can inject payloads like '" onmouseover="alert(document.cookie)"' to break out of the title attribute and inject malicious event handlers. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute when an administrator accesses the Calendar page and hovers over the malicious appointment. CVE record
- CVE-2026-14212, 26 Aug 2026
- The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password and take over their account. CVE record
- CVE-2026-14216, 26 Aug 2026
- The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks. CVE record
- CVE-2026-14213, 13 Aug 2026
- The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data. CVE record
- CVE-2026-14211, 10 Aug 2026
- The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers. CVE record
- CVE-2026-14214, 1 Aug 2026
- The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request. CVE record
- CVE-2026-14782, 16 Jul 2026
- The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with wpamelia-manager role, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2026-6449, 2 May 2026
- The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting' status. This makes it possible for unauthenticated attackers to approve any booking that is in 'waiting' status by sending a crafted request to the publicly-accessible admin-ajax endpoint. CVE record
- CVE-2026-5465, 7 Apr 2026
- The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the `UpdateProviderCommandHandler` failing to validate changes to the `externalId` field when a Provider (Employee) user updates their own profile. The `externalId` maps directly to a WordPress user ID and is passed to `wp_set_password()` and `wp_update_user()` without authorization checks. This makes it possible for authenticated attackers, with Provider-level (Employee) access and above, to take over any WordPress account - including Administrator - by injecting an arbitrary `externalId` value when updating their own provider profile. CVE record
- CVE-2026-4668, 1 Apr 2026
- The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and including, 2.1.2. This is due to insufficient escaping on the user-supplied `sort` parameter and lack of sufficient preparation on the existing SQL query in `PaymentRepository.php`, where the sort field is interpolated directly into an ORDER BY clause without sanitization or whitelist validation. PDO prepared statements do not protect ORDER BY column names. GET requests also skip Amelia's nonce validation entirely. This makes it possible for authenticated attackers, with Manager-level (`wpamelia-manager`) access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via time-based blind SQL injection. CVE record
- CVE-2026-2931, 26 Mar 2026
- The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with customer-level permissions or above to change user passwords and potentially take over administrator accounts. The vulnerability is in the pro plugin, which has the same slug. CVE record
- CVE-2025-14720, 9 Jan 2026
- The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark payments as refunded, trigger sending of queued notifications (emails/SMS/WhatsApp), and access debug information among other things. CVE record
- CVE-2025-12482, 16 Nov 2025
- The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2025-2578, 28 Mar 2025
- The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website. CVE record
- CVE-2024-6332, 5 Sep 2024
- The Booking for Appointments and Events Calendar - Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the 'ameliaButtonCommand' function in all versions up to, and including, Premium 7.7 and Lite 1.2.4. This makes it possible for unauthenticated attackers to access employee calendar details, including Google Calendar OAuth tokens in the premium version. CVE record
- CVE-2024-6552, 8 Aug 2024
- The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website. CVE record
- CVE-2024-6225, 21 Jun 2024
- The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.5 (and 7.5.1 for the Pro version) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. CVE record
- CVE-2024-1484, 13 Mar 2024
- The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the date parameters in all versions up to, and including, 1.0.98 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
- CVE-2023-6808, 5 Feb 2024
- The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2023-27918, 10 May 2023
- Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.0.76 allows a remote unauthenticated attacker to inject an arbitrary script by having a user who is logging in the WordPress where the product is installed visit a malicious URL. CVE record
What to do if you run Booking for Appointments and Events Calendar
If you run Booking for Appointments and Events Calendar, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Booking for Appointments and Events Calendar vulnerabilities
Free. We email you when a new vulnerability is published for Booking for Appointments and Events Calendar, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.