CVE · Medium

CVE-2022-0616 — Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0616 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.0.47 1.0.47 2022-02-23

CVE-2022-0616

The Amelia booking plugin versions prior to 1.0.47 lack proper cross-site request forgery protection on the customer deletion function, potentially allowing an attacker to trick an authenticated administrator into removing arbitrary customer accounts through a crafted request.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.