Executive brief
The Amelia booking plugin for WordPress is vulnerable to a security flaw that allows unauthorized individuals to access sensitive information. This plugin is commonly used by businesses to manage appointments and events; an exploit could lead to the exposure of private customer or system data. Organizations should update to version 2.2.1 or later to protect their data and maintain customer privacy.
Technical details
Amelia versions up to and including 2.2 are vulnerable to sensitive data exposure (CWE-201). The vulnerability allows an unauthenticated attacker to access sensitive information via the network without any user interaction. This is classified as a high-severity issue with a CVSS score of 7.5, as it can lead to a significant loss of confidentiality. The root cause involves the improper insertion of sensitive information into data sent to users who should not have access to it. The issue is resolved in version 2.2.1.
Affected products
- TMS Amelia <= 2.2
Timeline
- 2026-03-20: disclosed: Reported by Weerawat Pawanawiwat (ErbaZZ)
- 2026-04-23: patched: Patch released in version 2.2.1
- 2026-06-15: advisory: NVD and Patchstack advisory published