Executive brief
The Amelia plugin for WordPress, which is used to manage appointments and event bookings, contains a security flaw in its customer import feature. An authorized user with manager-level permissions could exploit this flaw to access sensitive information stored in the website's database. This could lead to the exposure of customer data or other internal site information.
Technical details
The 'Booking for Appointments and Events Calendar – Amelia' plugin for WordPress is vulnerable to a SQL injection vulnerability within the Customer Import functionality. The flaw exists in the UserRepository.php component due to insufficient escaping of user-supplied parameters and a lack of proper SQL query preparation. An authenticated attacker with the 'wpamelia-manager' role can inject malicious SQL commands to append additional queries to existing database operations. This allows for the unauthorized extraction of sensitive data from the WordPress database. The vulnerability affects all versions up to and including 2.4.3.
Affected products
- TMS-Plugins (Melograno) Booking for Appointments and Events Calendar – Amelia up to, and including, 2.4.3
Timeline
- 2026-07-16: disclosed: CVE published to NVD dataset