Executive brief
Amelia is a popular WordPress plugin for managing appointments and events bookings. The plugin before version 2.4.7 allows attackers to send queued email notifications and trigger post-booking actions without authentication. An attacker could spam customers and providers with unwanted notifications or execute automated workflows, disrupting business operations and damaging customer trust.
Technical details
The vulnerability is an authentication bypass (CWE-287) in the Amelia WordPress plugin's notification queue processing endpoint. The `/notifications/undelivered/send` AJAX action does not validate user authentication or capability checks before processing pending notifications and integration callbacks. An unauthenticated attacker can directly call `wp-admin/admin-ajax.php?action=wpamelia_api&call=/notifications/undelivered/send` to dispatch all queued email, SMS, and WhatsApp notifications and trigger post-booking automation chains. The attack requires no user interaction or valid credentials. A patch is available in version 2.4.7 and later.
Affected products
- Elated Themes Amelia before 2.4.7
Timeline
- 2026-08-24: disclosed
- 2026-08-26: patched: Version 2.4.7 and later
- 2026-08-26: advisory