Booking for Appointments and Events Calendar – Amelia <= 2.2 - Missing Authorization
Booking for Appointments and Events Calendar – Amelia
Minimum safe version
9.2
Update to 9.2 or later to address 32 fixable vulnerabilities
CVE-2026-6449
Booking for Appointments and Events Calendar – Amelia <= 2.2 - Unauthenticated Information Exposure
Amelia 1.2.18 - 1.2.36 - Unauthenticated Sensitive Information Exposure
Amelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change
Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter
CVE-2026-39487
Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter
CVE-2026-24963
CVE-2026-24967
CVE-2025-14720
CVE-2025-12482
Booking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure
CVE-2025-26965
CVE-2024-6332
CVE-2024-6552
WordPress Amelia Plugin <= 1.1.8 is vulnerable to Backdoor
CVE-2024-6225
CVE-2024-31425
CVE-2024-1484
CVE-2024-22298
CVE-2023-6808
WordPress Amelia Plugin <= 1.0.85 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-27918
CVE-2023-29427
CVE-2022-0837
CVE-2022-0834
CVE-2022-0825
CVE-2022-0720
CVE-2022-0687
CVE-2022-0627
CVE-2022-0616