Junglewise Threat Intelligence

CVE-2026-57702: Melograno Venture Studio Amelia SQL injection in ameliabooking

CVE-2026-57702 · Severity: critical · CVSS 9.3 · Published 2026-07-13

Technologies: Melograno Venture Studio Amelia.

Executive brief

Amelia is a popular WordPress plugin used by businesses to manage appointments, events, and customer bookings. A critical security flaw has been identified that allows unauthorized individuals to interact directly with the website's database without needing a password. This could lead to the theft of sensitive customer information, appointment records, and other private business data.

Technical details

The Amelia plugin (ameliabooking) for WordPress is vulnerable to Blind SQL Injection due to improper neutralization of special elements in SQL commands. The vulnerability exists in versions up to and including 2.4.2. An unauthenticated remote attacker can exploit this flaw by sending specially crafted web requests to the application, allowing them to execute arbitrary SQL queries against the backend database. This can be used to exfiltrate sensitive data, such as user credentials or customer booking details. The issue was addressed in version 2.4.3.

Affected products

  • Melograno Venture Studio Amelia <= 2.4.2

Timeline

  • 2026-06-10: disclosed: Reported by security researcher daroo
  • 2026-07-08: advisory: Patchstack published advisory and mitigation rules
  • 2026-07-13: advisory: CVE published to NVD dataset
  • patched: Fixed in version 2.4.3

References