PLUGIN SECURITY

Is Ameliabooking safe?

Amelia is a powerful booking plugin for appointments and events. Manage scheduling, calendars, and availability with an all-in-one booking system.

What this plugin does

  • Slug: ameliabooking
  • Author: Melograno Venture Studio
  • 90000+ active installs
  • 92/100 rating (785 reviews on wordpress.org)
  • 1565951 all-time downloads
  • On WordPress.org since 2018-12-11

appointmentsbookingbooking systemevent booking systemwpamelia

Maintenance status

  • Latest known version: 2.4.5
  • Last updated: 2026-08-20 2:47pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+

Known vulnerabilities

40 known CVEs on file for Ameliabooking.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-14216 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.7 Improper Authentication Unknown < 2.4.7 2.4.7 2026-08-26 ⚠ update needed
CVE-2026-14212 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 9.8 Authorization Bypass Through User-Controlled Key Unknown < 9.8 9.8 2026-08-26 ⚠ update needed
CVE-2026-6286 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.2.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 2.2.1 2.2.1 2026-08-14 ✓ fixed in latest
CVE-2026-14211 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 9.7 Authorization Bypass Through User-Controlled Key Unknown < 9.7 9.7 2026-08-10 ⚠ update needed
CVE-2026-14213 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.6 Authorization Bypass Through User-Controlled Key Unknown < 2.4.6 2.4.6 2026-08-07 ⚠ update needed
CVE-2026-14214 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.4 Improper Authentication Unknown < 2.4.4 2.4.4 2026-08-01 ✓ fixed in latest
CVE-2026-14782 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 4.9 < 2.4.4 2.4.4 2026-07-16 ✓ fixed in latest
CVE-2026-57702 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.3 Critical 9.3 < 2.4.3 2.4.3 2026-07-08 ✓ fixed in latest
+ 37 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-48889 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4 Incorrect Privilege Assignment High 8.8 < 2.4 2.4 2026-06-02 ✓ fixed in latest
CVE-2026-6449 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.3 Improper Authorization Medium 5.3 < 2.3 2.3 2026-05-01 ✓ fixed in latest
CVE-2026-40795 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.2.1 Missing Authorization Medium 6.5 < 2.2.1 2.2.1 2026-04-28 ✓ fixed in latest
CVE-2026-40789 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.2.1 Insertion of Sensitive Information Into Sent Data High 7.5 < 2.2.1 2.2.1 2026-04-23 ✓ fixed in latest
CVE-2026-39487 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.1.2 High 7.6 < 2.1.2 2.1.2 2026-03-25 ✓ fixed in latest
CVE-2026-24963 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0 Incorrect Privilege Assignment High 7.2 < 2.0 2.0 2026-03-04 ✓ fixed in latest
CVE-2026-24967 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0 Missing Authorization Medium 5.3 < 2.0 2.0 2026-01-11 ✓ fixed in latest
CVE-2025-14720 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0.0 Missing Authorization Medium 5.3 < 2.0.0 2.0.0 2026-01-08 ✓ fixed in latest
CVE-2025-12482 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.36 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 1.2.36 1.2.36 2025-11-15 ✓ fixed in latest
CVE-2025-26965 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.17 Authorization Bypass Through User-Controlled Key Medium 5.3 < 1.2.17 1.2.17 2025-02-23 ✓ fixed in latest
CVE-2024-6332 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.5 Missing Authorization Medium 6.5 < 1.2.5 1.2.5 2024-09-04 ✓ fixed in latest
CVE-2024-6552 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.1 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 1.2.1 1.2.1 2024-08-07 ✓ fixed in latest
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.1.9 Unknown < 1.1.9 1.1.9 2024-07-03 ✓ fixed in latest
CVE-2024-6225 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.1.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.1.6 1.1.6 2024-06-20 ✓ fixed in latest
CVE-2024-31425 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.96 Cross-Site Request Forgery (CSRF) Medium 5.4 < 1.0.96 1.0.96 2024-04-10 ✓ fixed in latest
CVE-2024-1484 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.99 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.0.99 1.0.99 2024-02-29 ✓ fixed in latest
CVE-2023-6808 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.94 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.0.94 1.0.94 2024-01-18 ✓ fixed in latest
CVE-2024-22298 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.99 Missing Authorization Medium 5.3 < 1.0.99 1.0.99 2024-01-17 ✓ fixed in latest
CVE-2023-50860 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.86 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 1.0.86 1.0.86 2023-12-22 ✓ fixed in latest
CVE-2023-49282 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.37 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.4 < 1.2.37 1.2.37 2023-12-05 ✓ fixed in latest
CVE-2023-29427 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.76 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 1.0.76 1.0.76 2023-04-06 ✓ fixed in latest
CVE-2023-27918, CVE-2023-29427 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.76 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.0.76 1.0.76 2023-04-06 ✓ fixed in latest
CVE-2022-0825 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.49 Incorrect Authorization Medium 5.4 < 1.0.49 1.0.49 2022-03-14 ✓ fixed in latest
CVE-2022-0837 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.48 Missing Authorization Medium 5.4 < 1.0.48 1.0.48 2022-03-14 ✓ fixed in latest
CVE-2022-0834 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.0.47 1.0.47 2022-03-02 ✓ fixed in latest
CVE-2022-0720 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 Incorrect Authorization Medium 5.4 < 1.0.47 1.0.47 2022-03-01 ✓ fixed in latest
CVE-2022-0616 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.0.47 1.0.47 2022-02-23 ✓ fixed in latest
CVE-2022-0627 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.0.47 1.0.47 2022-02-23 ✓ fixed in latest
CVE-2022-0687 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.0.47 Unrestricted Upload of File with Dangerous Type High 8.8 < 1.0.47 1.0.47 2022-02-23 ✓ fixed in latest
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.20 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 1.2.20 1.2.20 0000-00-00 ✓ fixed in latest
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.1.3 Unknown < 2.1.3 2.1.3 0000-00-00 ✓ fixed in latest
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.2 Unknown < 2.2 2.2 0000-00-00 ✓ fixed in latest
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 9.2 Unknown < 9.2 9.2 0000-00-00 ⚠ update needed
CVE-2025-2578 Booking for Appointments and Events Calendar – Amelia < 1.2.20 - Unauthenticated Full Path Disclosure Unknown < 1.2.20 1.2.20 ✓ fixed in latest
CVE-2026-2931 Amelia Booking 8.3 - 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change Unknown < 9.2 9.2 ⚠ update needed
CVE-2026-4668 Amelia < 2.1.3 - Authenticated (Manager+) SQL Injection via 'sort' Parameter Unknown < 2.1.3 2.1.3 ✓ fixed in latest
CVE-2026-5465 Amelia < 2.2 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter Unknown < 2.2 2.2 ✓ fixed in latest

How to fix it

Keep Ameliabooking updated — 2.4.5 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.