Executive brief
Amelia is a popular WordPress plugin for managing appointment bookings and event calendars. The plugin fails to properly validate payment confirmations, allowing attackers to create legitimate-looking appointment bookings without actually paying. This could result in lost revenue and service disruption.
Technical details
The vulnerability is an authorization bypass in the payment validation logic. The plugin accepts a client-supplied package-redemption identifier as proof of payment without server-side validation, allowing unauthenticated attackers to forge valid booking confirmations. The attack requires no authentication or user interaction—an attacker can directly submit a booking with a spoofed payment token. This enables fraudulent appointment creation and revenue loss. The vulnerability affects all versions up to 2.4.5.
Affected products
- WordPress Booking for Appointments and Events Calendar – Amelia up to 2.4.5
Timeline
- 2026-09-17: disclosed