Executive brief
Amelia is a popular WordPress plugin used for managing appointments and event bookings. A security vulnerability in this plugin could allow an attacker with administrative or high-level privileges to interact directly with the website's database. This could lead to the unauthorized extraction of sensitive information, such as customer data or site configuration details.
Technical details
A Blind SQL Injection vulnerability exists in the ameliabooking (Amelia) plugin for WordPress through version 2.1.1. The flaw stems from improper neutralization of special elements used in SQL commands (CWE-89). An attacker with high privileges (such as a custom role or administrator) can exploit this over the network without user interaction to execute arbitrary SQL queries. This can be used to exfiltrate sensitive data from the database. The issue is addressed in version 2.1.2.
Affected products
- ameliabooking Amelia <= 2.1.1
Timeline
- 2026-02-23: other: Vulnerability reported by researcher daroo
- 2026-03-25: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD
- 2026-03-25: patched: Patch released in version 2.1.2