Junglewise Threat Intelligence

CVE-2026-62112: Amelia SQL Injection vulnerability in Editor role

CVE-2026-62112 · Severity: high · CVSS 7.6 · Published 2026-09-11

Executive brief

Amelia is a popular WordPress booking and event management plugin. A SQL injection vulnerability in versions 2.4.9 and earlier allows users with Editor privileges to read, modify, or delete the entire website database, including customer booking data and site credentials. This could lead to unauthorized access, data theft, or complete site takeover.

Technical details

This is a SQL injection vulnerability in the Amelia WordPress plugin affecting versions 2.4.9 and earlier. The vulnerability resides in functionality accessible to Editor-role users, allowing them to inject arbitrary SQL commands. The attack requires user authentication (Editor role or higher) but no additional interaction. A successful exploit permits attackers to execute arbitrary database queries, enabling exfiltration, modification, or deletion of all data stored in the WordPress database. The vulnerability has been patched in version 2.4.10 or later.

Affected products

  • Amelia Amelia <=2.4.9

Timeline

  • 2026-09-11: disclosed: Vulnerability published by Patchstack
  • 2026-09-11: patched: Patch released in version 2.4.10

References