+ 27 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-24967
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0 |
Falta de control de autorización |
Media
5,3
|
< 2.0
|
2.0 |
2026-01-11 |
✓ corregido en la última versión
|
|
CVE-2025-14720
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0.0 |
Falta de control de autorización |
Media
5,3
|
< 2.0.0
|
2.0.0 |
2026-01-08 |
✓ corregido en la última versión
|
|
CVE-2025-12482
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.36 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Alta
7,5
|
< 1.2.36
|
1.2.36 |
2025-11-15 |
✓ corregido en la última versión
|
|
CVE-2025-26965
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.17 |
Elusión de autorización mediante una clave controlada por el usuario |
Media
5,3
|
< 1.2.17
|
1.2.17 |
2025-02-23 |
✓ corregido en la última versión
|
|
CVE-2024-6332
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.5 |
Falta de control de autorización |
Media
6,5
|
< 1.2.5
|
1.2.5 |
2024-09-04 |
✓ corregido en la última versión
|
|
CVE-2024-6552
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.1 |
Exposición de información sensible a un actor no autorizado |
Media
5,3
|
< 1.2.1
|
1.2.1 |
2024-08-07 |
✓ corregido en la última versión
|
|
—
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.1.9 |
— |
Desconocido
|
< 1.1.9
|
1.1.9 |
2024-07-03 |
✓ corregido en la última versión
|
|
CVE-2024-6225
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.1.6 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 1.1.6
|
1.1.6 |
2024-06-20 |
✓ corregido en la última versión
|
|
CVE-2024-31425
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.96 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
5,4
|
< 1.0.96
|
1.0.96 |
2024-04-10 |
✓ corregido en la última versión
|
|
CVE-2024-1484
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.99 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 1.0.99
|
1.0.99 |
2024-02-29 |
✓ corregido en la última versión
|
|
CVE-2023-6808
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.94 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 1.0.94
|
1.0.94 |
2024-01-18 |
✓ corregido en la última versión
|
|
CVE-2024-22298
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.99 |
Falta de control de autorización |
Media
5,3
|
< 1.0.99
|
1.0.99 |
2024-01-17 |
✓ corregido en la última versión
|
|
CVE-2023-50860
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.86 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 1.0.86
|
1.0.86 |
2023-12-22 |
✓ corregido en la última versión
|
|
CVE-2023-49282
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.37 |
Exposición de información sensible a un actor no autorizado |
Media
5,4
|
< 1.2.37
|
1.2.37 |
2023-12-05 |
✓ corregido en la última versión
|
|
CVE-2023-29427
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.76 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Alta
7,1
|
< 1.0.76
|
1.0.76 |
2023-04-06 |
✓ corregido en la última versión
|
|
CVE-2023-27918, CVE-2023-29427
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.76 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 1.0.76
|
1.0.76 |
2023-04-06 |
✓ corregido en la última versión
|
|
CVE-2022-0825
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.49 |
Autorización incorrecta |
Media
5,4
|
< 1.0.49
|
1.0.49 |
2022-03-14 |
✓ corregido en la última versión
|
|
CVE-2022-0837
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.48 |
Falta de control de autorización |
Media
5,4
|
< 1.0.48
|
1.0.48 |
2022-03-14 |
✓ corregido en la última versión
|
|
CVE-2022-0834
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 1.0.47
|
1.0.47 |
2022-03-02 |
✓ corregido en la última versión
|
|
CVE-2022-0720
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 |
Autorización incorrecta |
Media
5,4
|
< 1.0.47
|
1.0.47 |
2022-03-01 |
✓ corregido en la última versión
|
|
CVE-2022-0616
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 1.0.47
|
1.0.47 |
2022-02-23 |
✓ corregido en la última versión
|
|
CVE-2022-0627
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 1.0.47
|
1.0.47 |
2022-02-23 |
✓ corregido en la última versión
|
|
CVE-2022-0687
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 |
Carga de archivos sin restricción de tipo peligroso |
Alta
8,8
|
< 1.0.47
|
1.0.47 |
2022-02-23 |
✓ corregido en la última versión
|
|
CVE-2025-2578
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.20 |
Exposición de información sensible a un actor no autorizado |
Media
5,3
|
< 1.2.20
|
1.2.20 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-4668
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.1.3 |
— |
Desconocido
|
< 2.1.3
|
2.1.3 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-5465
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.2 |
— |
Desconocido
|
< 2.2
|
2.2 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-2931
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 9.2 |
— |
Desconocido
|
< 9.2
|
9.2 |
0000-00-00 |
⚠ necesita actualización
|
CVE-2026-24967
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-14720
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark payments as refunded, trigger sending of queued notifications (emails/SMS/WhatsApp), and access debug information among other things.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-12482
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-26965
The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.16 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-6332
The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the 'ameliaButtonCommand' function in all versions up to, and including, Premium 7.7 and Lite 1.2.3. This makes it possible for unauthenticated attackers to access employee calendar details, including Google Calendar OAuth tokens in the premium version.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-6552
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.1.9
<p>WordPress Amelia Plugin <= 1.1.8 is vulnerable to Backdoor</p><p>Software: Amelia</p><p>Link: https://wordpress.org/plugins/ameliabooking/#developers</p><p>Affected Version <= 1.1.8</p>
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-6225
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.5 (and 7.5.1 for the Pro version) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-31425
Update the WordPress Amelia plugin to the latest available version (at least 1.0.96).
Yudistira Arya discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 1.0.96.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-1484
Update the WordPress Amelia plugin to the latest available version (at least 1.0.99).
Muhammad Hassham Nagori discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.0.99.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-6808
Update the WordPress Amelia plugin to the latest available version (at least 1.0.94).
Ngô Thiên An (ancorn_) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.0.94.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-22298
No patched version is available.
Abdi Pranata discovered and reported this Broken Access Control vulnerability in WordPress Amelia Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has not been known to be fixed yet.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-50860
Update the WordPress Amelia plugin to the latest available version (at least 1.0.86).
Ngô Thiên An (ancorn_ from VNPT-VCI) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.0.86.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-49282
msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php. The phpInfo function exposes system information. The vulnerability affects the GetPhpInfo.php script of the PHP SDK which contains a call to the phpinfo() function. This vulnerability requires a misconfiguration of the server to be present so it can be exploited. For example, making the PHP application’s /vendor directory web accessible. The combination of the vulnerability and the server misconfiguration would allow an attacker to craft an HTTP request that executes the phpinfo() method. The attacker would then be able to get access to system information like configuration, modules, and environment variables and later on use the compromised secrets to access additional data. This problem has been patched in versions 1.109.1 and 2.0.0-RC5. If an immediate deployment with the updated vendor package is not available, you can perform the following temporary workarounds: delete the `vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php` file, remove access to the `/vendor` directory, or disable the phpinfo function.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-29427
Update the WordPress Amelia plugin to the latest available version (at least 1.0.76).
minhtuanact discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Amelia Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.0.76.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-27918, CVE-2023-29427
The Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'code' parameter in versions up to, and including, 1.0.75 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2023-27918 may be a duplicate.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-0825
The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2022-0837
The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment history. A malicious actor can abuse this vulnerability to drain out the account balance by keep sending SMS notification.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2022-0834
The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user accesses the booking calendar with the date the attacker has injected the malicious payload into. This affects versions up to and including 1.0.46.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2022-0720
The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2022-0616
The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2022-0627
The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2022-0687
The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-2578
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-4668
The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and including, 2.1.2. This is due to insufficient escaping on the user-supplied `sort` parameter and lack of sufficient preparation on the existing SQL query in `PaymentRepository.php`, where the sort field is interpolated directly into an ORDER BY clause without sanitization or whitelist validation. PDO prepared statements do not protect ORDER BY column names. GET requests also skip Amelia's nonce validation entirely. This makes it possible for authenticated attackers, with Manager-level (`wpamelia-manager`) access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via time-based blind SQL injection.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-5465
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the `UpdateProviderCommandHandler` failing to validate changes to the `externalId` field when a Provider (Employee) user updates their own profile. The `externalId` maps directly to a WordPress user ID and is passed to `wp_set_password()` and `wp_update_user()` without authorization checks. This makes it possible for authenticated attackers, with Provider-level (Employee) access and above, to take over any WordPress account — including Administrator — by injecting an arbitrary `externalId` value when updating their own provider profile.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-2931
The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions 8.3 to 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with customer-level permissions or above to change user passwords and potentially take over administrator accounts. The vulnerability is in the pro plugin, which has the same slug.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Mantén Ameliabooking actualizado — 2.4.4 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.