PLUGIN SECURITY
Is Ameliabooking safe?
Amelia is a powerful booking plugin for appointments and events. Manage scheduling, calendars, and availability with an all-in-one booking system.
What this plugin does
- Slug:
ameliabooking - Author: Melograno Venture Studio
- 90000+ active installs
- 92/100 rating (785 reviews on wordpress.org)
- 1565951 all-time downloads
- On WordPress.org since 2018-12-11
appointmentsbookingbooking systemevent booking systemwpamelia
Maintenance status
- Latest known version: 2.4.5
- Last updated: 2026-08-20 2:47pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
Known vulnerabilities
40 known CVEs on file for Ameliabooking.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-14216 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.7 | Improper Authentication | Unknown | < 2.4.7 | 2.4.7 | 2026-08-26 | ⚠ update needed |
| CVE-2026-14212 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 9.8 | Authorization Bypass Through User-Controlled Key | Unknown | < 9.8 | 9.8 | 2026-08-26 | ⚠ update needed |
| CVE-2026-6286 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.2.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.2 | < 2.2.1 | 2.2.1 | 2026-08-14 | ✓ fixed in latest |
| CVE-2026-14211 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 9.7 | Authorization Bypass Through User-Controlled Key | Unknown | < 9.7 | 9.7 | 2026-08-10 | ⚠ update needed |
| CVE-2026-14213 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.6 | Authorization Bypass Through User-Controlled Key | Unknown | < 2.4.6 | 2.4.6 | 2026-08-07 | ⚠ update needed |
| CVE-2026-14214 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.4 | Improper Authentication | Unknown | < 2.4.4 | 2.4.4 | 2026-08-01 | ✓ fixed in latest |
| CVE-2026-14782 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.4 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 4.9 | < 2.4.4 | 2.4.4 | 2026-07-16 | ✓ fixed in latest |
| CVE-2026-57702 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.3 | — | Critical 9.3 | < 2.4.3 | 2.4.3 | 2026-07-08 | ✓ fixed in latest |
+ 37 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-48889 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4 | Incorrect Privilege Assignment | High 8.8 | < 2.4 | 2.4 | 2026-06-02 | ✓ fixed in latest |
| CVE-2026-6449 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.3 | Improper Authorization | Medium 5.3 | < 2.3 | 2.3 | 2026-05-01 | ✓ fixed in latest |
| CVE-2026-40795 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.2.1 | Missing Authorization | Medium 6.5 | < 2.2.1 | 2.2.1 | 2026-04-28 | ✓ fixed in latest |
| CVE-2026-40789 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.2.1 | Insertion of Sensitive Information Into Sent Data | High 7.5 | < 2.2.1 | 2.2.1 | 2026-04-23 | ✓ fixed in latest |
| CVE-2026-39487 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.1.2 | — | High 7.6 | < 2.1.2 | 2.1.2 | 2026-03-25 | ✓ fixed in latest |
| CVE-2026-24963 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0 | Incorrect Privilege Assignment | High 7.2 | < 2.0 | 2.0 | 2026-03-04 | ✓ fixed in latest |
| CVE-2026-24967 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0 | Missing Authorization | Medium 5.3 | < 2.0 | 2.0 | 2026-01-11 | ✓ fixed in latest |
| CVE-2025-14720 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0.0 | Missing Authorization | Medium 5.3 | < 2.0.0 | 2.0.0 | 2026-01-08 | ✓ fixed in latest |
| CVE-2025-12482 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.36 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.5 | < 1.2.36 | 1.2.36 | 2025-11-15 | ✓ fixed in latest |
| CVE-2025-26965 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.17 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 1.2.17 | 1.2.17 | 2025-02-23 | ✓ fixed in latest |
| CVE-2024-6332 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.5 | Missing Authorization | Medium 6.5 | < 1.2.5 | 1.2.5 | 2024-09-04 | ✓ fixed in latest |
| CVE-2024-6552 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.1 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 1.2.1 | 1.2.1 | 2024-08-07 | ✓ fixed in latest |
| — | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.1.9 | — | Unknown | < 1.1.9 | 1.1.9 | 2024-07-03 | ✓ fixed in latest |
| CVE-2024-6225 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.1.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 1.1.6 | 1.1.6 | 2024-06-20 | ✓ fixed in latest |
| CVE-2024-31425 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.96 | Cross-Site Request Forgery (CSRF) | Medium 5.4 | < 1.0.96 | 1.0.96 | 2024-04-10 | ✓ fixed in latest |
| CVE-2024-1484 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.99 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.0.99 | 1.0.99 | 2024-02-29 | ✓ fixed in latest |
| CVE-2023-6808 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.94 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.0.94 | 1.0.94 | 2024-01-18 | ✓ fixed in latest |
| CVE-2024-22298 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.99 | Missing Authorization | Medium 5.3 | < 1.0.99 | 1.0.99 | 2024-01-17 | ✓ fixed in latest |
| CVE-2023-50860 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.86 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 1.0.86 | 1.0.86 | 2023-12-22 | ✓ fixed in latest |
| CVE-2023-49282 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.37 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.4 | < 1.2.37 | 1.2.37 | 2023-12-05 | ✓ fixed in latest |
| CVE-2023-29427 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.76 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 1.0.76 | 1.0.76 | 2023-04-06 | ✓ fixed in latest |
| CVE-2023-27918, CVE-2023-29427 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.76 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.0.76 | 1.0.76 | 2023-04-06 | ✓ fixed in latest |
| CVE-2022-0825 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.49 | Incorrect Authorization | Medium 5.4 | < 1.0.49 | 1.0.49 | 2022-03-14 | ✓ fixed in latest |
| CVE-2022-0837 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.48 | Missing Authorization | Medium 5.4 | < 1.0.48 | 1.0.48 | 2022-03-14 | ✓ fixed in latest |
| CVE-2022-0834 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.0.47 | 1.0.47 | 2022-03-02 | ✓ fixed in latest |
| CVE-2022-0720 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 | Incorrect Authorization | Medium 5.4 | < 1.0.47 | 1.0.47 | 2022-03-01 | ✓ fixed in latest |
| CVE-2022-0616 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 1.0.47 | 1.0.47 | 2022-02-23 | ✓ fixed in latest |
| CVE-2022-0627 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.0.47 | 1.0.47 | 2022-02-23 | ✓ fixed in latest |
| CVE-2022-0687 | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 | Unrestricted Upload of File with Dangerous Type | High 8.8 | < 1.0.47 | 1.0.47 | 2022-02-23 | ✓ fixed in latest |
| — | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.20 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 1.2.20 | 1.2.20 | 0000-00-00 | ✓ fixed in latest |
| — | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.1.3 | — | Unknown | < 2.1.3 | 2.1.3 | 0000-00-00 | ✓ fixed in latest |
| — | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.2 | — | Unknown | < 2.2 | 2.2 | 0000-00-00 | ✓ fixed in latest |
| — | Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 9.2 | — | Unknown | < 9.2 | 9.2 | 0000-00-00 | ⚠ update needed |
| CVE-2025-2578 | Booking for Appointments and Events Calendar – Amelia < 1.2.20 - Unauthenticated Full Path Disclosure | — | Unknown | < 1.2.20 | 1.2.20 | — | ✓ fixed in latest |
| CVE-2026-2931 | Amelia Booking 8.3 - 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change | — | Unknown | < 9.2 | 9.2 | — | ⚠ update needed |
| CVE-2026-4668 | Amelia < 2.1.3 - Authenticated (Manager+) SQL Injection via 'sort' Parameter | — | Unknown | < 2.1.3 | 2.1.3 | — | ✓ fixed in latest |
| CVE-2026-5465 | Amelia < 2.2 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter | — | Unknown | < 2.2 | 2.2 | — | ✓ fixed in latest |
How to fix it
Keep Ameliabooking updated — 2.4.5 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress — 100000+ active installs — 98/100 (98) — max PHP 8.4
- Online Scheduling and Appointment Booking System – Bookly — 60000+ active installs — 88/100 (575) — max PHP <8.0
- Simply Schedule Appointments — 50000+ active installs — 100/100 (155) — max PHP 8.4
- SimplyBook.me – Booking and reservations calendar — 30000+ active installs — 90/100 (17) — max PHP 8.4
- Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution — 20000+ active installs — 94/100 (43)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.