CVE · Medium

CVE-2025-26965 — Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.17

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-26965 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.17 Authorization Bypass Through User-Controlled Key Medium 5.3 < 1.2.17 1.2.17 2025-02-23

CVE-2025-26965

The Amelia plugin for WordPress contains a security flaw that allows unauthorized access to sensitive functionality through manipulation of a user-input variable without proper verification. This vulnerability affects all versions up to and including 1.2.16, potentially enabling malicious actors to bypass authentication checks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.