CVE · Medium

CVE-2022-0720 — Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0720 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 Incorrect Authorization Medium 5.4 < 1.0.47 1.0.47 2022-03-01

CVE-2022-0720

The Amelia appointment booking plugin before version 1.0.47 lacks sufficient authorization controls when handling appointment data, enabling any customer to modify bookings belonging to other users and access confidential booking details including the booker's full name and telephone number.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.