CVE · Medium

CVE-2026-24967 — Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-24967 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0 Missing Authorization Medium 5.3 < 2.0 2.0 2026-01-11

CVE-2026-24967

A security flaw has been identified in the Booking for Appointments and Events Calendar - Amelia plugin used with WordPress sites. The issue arises from inadequate permission checks on a specific function within plugin versions running 1.2.38 or earlier, allowing potential exploitation by unverified attackers. This can result in unauthorized actions being performed on affected websites.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.