Executive brief
The Amelia booking plugin for WordPress, used for managing appointments and events, contains a security flaw in its customer import feature. An authorized user with the 'Amelia Manager' role can exploit this to modify sensitive information in any user's record, potentially leading to unauthorized data changes. This issue has been resolved in version 2.4.4.
Technical details
A mass assignment vulnerability exists in the Amelia plugin (ameliabooking) before version 2.4.4. The customer import functionality fails to restrict which database fields can be written, allowing an attacker with 'Amelia Manager' privileges to supply arbitrary columns in the import request. This can be used to modify sensitive user data across the entire database. The vulnerability is tracked as CWE-287/CWE-915 and requires authentication with specific plugin-level manager permissions. A fix is available in version 2.4.4.
Affected products
- Unknown Booking for Appointments and Events Calendar (Amelia) < 2.4.4
Timeline
- 2026-07-20: disclosed
- 2026-07-20: advisory
- 2026-08-01: patched: NVD publication date; fix available in 2.4.4