CVE Database /
CVE-2024-6552
CVE · Medium
CVE-2024-6552 — Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-6552
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.1 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
5.3
|
< 1.2.1
|
1.2.1 |
2024-08-07 |
—
|
CVE-2024-6552
The Amelia plugin for WordPress contains a flaw in versions 1.2 and earlier that allows unauthorized access to sensitive file paths. This occurs because the plugin's use of Symfony leaves error messages visible during testing, potentially revealing the application's directory structure. While this information alone is not exploitable, it could be used in conjunction with other vulnerabilities to compromise an affected site.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings