WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Ameliabooking?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Ameliabooking — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: ameliabooking
  • 90000+ instalaciones activas

appointmentsbookingbooking systemevent booking systemwpamelia

Estado de mantenimiento

  • Última versión conocida: 2.4.4
  • Requiere PHP: 7.4+

Vulnerabilidades conocidas

34 CVEs conocidos registrados para Ameliabooking.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-14782 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.4 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Media 4,9 < 2.4.4 2.4.4 2026-07-16 ✓ corregido en la última versión
CVE-2026-57702 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.3 Crítica 9,3 < 2.4.3 2.4.3 2026-07-08 ✓ corregido en la última versión
CVE-2026-48889 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4 Asignación incorrecta de privilegios Alta 8,8 < 2.4 2.4 2026-06-02 ✓ corregido en la última versión
CVE-2026-6449 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.3 Autorización indebida Media 5,3 < 2.3 2.3 2026-05-01 ✓ corregido en la última versión
CVE-2026-40795 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.2.1 Falta de control de autorización Media 6,5 < 2.2.1 2.2.1 2026-04-28 ✓ corregido en la última versión
CVE-2026-40789 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.2.1 Inserción de información sensible en los datos enviados Alta 7,5 < 2.2.1 2.2.1 2026-04-23 ✓ corregido en la última versión
CVE-2026-39487 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.1.2 Alta 7,6 < 2.1.2 2.1.2 2026-03-25 ✓ corregido en la última versión
CVE-2026-24963 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0 Asignación incorrecta de privilegios Alta 7,2 < 2.0 2.0 2026-03-04 ✓ corregido en la última versión

CVE-2026-14782

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with wpamelia-manager role, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-57702

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-48889

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-6449

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting' status. This makes it possible for unauthenticated attackers to approve any booking that is in 'waiting' status by sending a crafted request to the publicly-accessible admin-ajax endpoint.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-40795

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-40789

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-39487

The Amelia plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom role-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-24963

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.38. This makes it possible for authenticated attackers, with employee-level access and above, to elevate their privileges to that of an administrator.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 27 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-24967 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0 Falta de control de autorización Media 5,3 < 2.0 2.0 2026-01-11 ✓ corregido en la última versión
CVE-2025-14720 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0.0 Falta de control de autorización Media 5,3 < 2.0.0 2.0.0 2026-01-08 ✓ corregido en la última versión
CVE-2025-12482 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.36 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 7,5 < 1.2.36 1.2.36 2025-11-15 ✓ corregido en la última versión
CVE-2025-26965 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.17 Elusión de autorización mediante una clave controlada por el usuario Media 5,3 < 1.2.17 1.2.17 2025-02-23 ✓ corregido en la última versión
CVE-2024-6332 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.5 Falta de control de autorización Media 6,5 < 1.2.5 1.2.5 2024-09-04 ✓ corregido en la última versión
CVE-2024-6552 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.1 Exposición de información sensible a un actor no autorizado Media 5,3 < 1.2.1 1.2.1 2024-08-07 ✓ corregido en la última versión
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.1.9 Desconocido < 1.1.9 1.1.9 2024-07-03 ✓ corregido en la última versión
CVE-2024-6225 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.1.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 1.1.6 1.1.6 2024-06-20 ✓ corregido en la última versión
CVE-2024-31425 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.96 Falsificación de petición en sitios cruzados (CSRF) Media 5,4 < 1.0.96 1.0.96 2024-04-10 ✓ corregido en la última versión
CVE-2024-1484 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.99 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 1.0.99 1.0.99 2024-02-29 ✓ corregido en la última versión
CVE-2023-6808 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.94 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.0.94 1.0.94 2024-01-18 ✓ corregido en la última versión
CVE-2024-22298 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.99 Falta de control de autorización Media 5,3 < 1.0.99 1.0.99 2024-01-17 ✓ corregido en la última versión
CVE-2023-50860 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.86 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 1.0.86 1.0.86 2023-12-22 ✓ corregido en la última versión
CVE-2023-49282 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.37 Exposición de información sensible a un actor no autorizado Media 5,4 < 1.2.37 1.2.37 2023-12-05 ✓ corregido en la última versión
CVE-2023-29427 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.76 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 7,1 < 1.0.76 1.0.76 2023-04-06 ✓ corregido en la última versión
CVE-2023-27918, CVE-2023-29427 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.76 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 1.0.76 1.0.76 2023-04-06 ✓ corregido en la última versión
CVE-2022-0825 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.49 Autorización incorrecta Media 5,4 < 1.0.49 1.0.49 2022-03-14 ✓ corregido en la última versión
CVE-2022-0837 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.48 Falta de control de autorización Media 5,4 < 1.0.48 1.0.48 2022-03-14 ✓ corregido en la última versión
CVE-2022-0834 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.0.47 1.0.47 2022-03-02 ✓ corregido en la última versión
CVE-2022-0720 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 Autorización incorrecta Media 5,4 < 1.0.47 1.0.47 2022-03-01 ✓ corregido en la última versión
CVE-2022-0616 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 1.0.47 1.0.47 2022-02-23 ✓ corregido en la última versión
CVE-2022-0627 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 1.0.47 1.0.47 2022-02-23 ✓ corregido en la última versión
CVE-2022-0687 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 Carga de archivos sin restricción de tipo peligroso Alta 8,8 < 1.0.47 1.0.47 2022-02-23 ✓ corregido en la última versión
CVE-2025-2578 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.20 Exposición de información sensible a un actor no autorizado Media 5,3 < 1.2.20 1.2.20 0000-00-00 ✓ corregido en la última versión
CVE-2026-4668 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.1.3 Desconocido < 2.1.3 2.1.3 0000-00-00 ✓ corregido en la última versión
CVE-2026-5465 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.2 Desconocido < 2.2 2.2 0000-00-00 ✓ corregido en la última versión
CVE-2026-2931 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 9.2 Desconocido < 9.2 9.2 0000-00-00 ⚠ necesita actualización

CVE-2026-24967

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-14720

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark payments as refunded, trigger sending of queued notifications (emails/SMS/WhatsApp), and access debug information among other things.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-12482

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-26965

The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.16 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-6332

The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the 'ameliaButtonCommand' function in all versions up to, and including, Premium 7.7 and Lite 1.2.3. This makes it possible for unauthenticated attackers to access employee calendar details, including Google Calendar OAuth tokens in the premium version.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-6552

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.1.9

<p>WordPress Amelia Plugin <= 1.1.8 is vulnerable to Backdoor</p><p>Software: Amelia</p><p>Link: https://wordpress.org/plugins/ameliabooking/#developers</p><p>Affected Version <= 1.1.8</p>

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-6225

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.5 (and 7.5.1 for the Pro version) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-31425

Update the WordPress Amelia plugin to the latest available version (at least 1.0.96). Yudistira Arya discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 1.0.96. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1484

Update the WordPress Amelia plugin to the latest available version (at least 1.0.99). Muhammad Hassham Nagori discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.0.99. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-6808

Update the WordPress Amelia plugin to the latest available version (at least 1.0.94). Ngô Thiên An (ancorn_) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.0.94. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-22298

No patched version is available. Abdi Pranata discovered and reported this Broken Access Control vulnerability in WordPress Amelia Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has not been known to be fixed yet. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-50860

Update the WordPress Amelia plugin to the latest available version (at least 1.0.86). Ngô Thiên An (ancorn_ from VNPT-VCI) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.0.86. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-49282

msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php. The phpInfo function exposes system information. The vulnerability affects the GetPhpInfo.php script of the PHP SDK which contains a call to the phpinfo() function. This vulnerability requires a misconfiguration of the server to be present so it can be exploited. For example, making the PHP application’s /vendor directory web accessible. The combination of the vulnerability and the server misconfiguration would allow an attacker to craft an HTTP request that executes the phpinfo() method. The attacker would then be able to get access to system information like configuration, modules, and environment variables and later on use the compromised secrets to access additional data. This problem has been patched in versions 1.109.1 and 2.0.0-RC5. If an immediate deployment with the updated vendor package is not available, you can perform the following temporary workarounds: delete the `vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php` file, remove access to the `/vendor` directory, or disable the phpinfo function.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-29427

Update the WordPress Amelia plugin to the latest available version (at least 1.0.76). minhtuanact discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.0.76.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-27918, CVE-2023-29427

The Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'code' parameter in versions up to, and including, 1.0.75 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2023-27918 may be a duplicate.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-0825

The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-0837

The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment history. A malicious actor can abuse this vulnerability to drain out the account balance by keep sending SMS notification.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-0834

The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user accesses the booking calendar with the date the attacker has injected the malicious payload into. This affects versions up to and including 1.0.46.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-0720

The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-0616

The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-0627

The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-0687

The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-2578

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-4668

The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and including, 2.1.2. This is due to insufficient escaping on the user-supplied `sort` parameter and lack of sufficient preparation on the existing SQL query in `PaymentRepository.php`, where the sort field is interpolated directly into an ORDER BY clause without sanitization or whitelist validation. PDO prepared statements do not protect ORDER BY column names. GET requests also skip Amelia's nonce validation entirely. This makes it possible for authenticated attackers, with Manager-level (`wpamelia-manager`) access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via time-based blind SQL injection.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-5465

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the `UpdateProviderCommandHandler` failing to validate changes to the `externalId` field when a Provider (Employee) user updates their own profile. The `externalId` maps directly to a WordPress user ID and is passed to `wp_set_password()` and `wp_update_user()` without authorization checks. This makes it possible for authenticated attackers, with Provider-level (Employee) access and above, to take over any WordPress account — including Administrator — by injecting an arbitrary `externalId` value when updating their own provider profile.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-2931

The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions 8.3 to 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with customer-level permissions or above to change user passwords and potentially take over administrator accounts. The vulnerability is in the pro plugin, which has the same slug.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Cómo solucionarlo

Mantén Ameliabooking actualizado — 2.4.4 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.