WordPress · Amelia · CVE-2026-14782
**Name of the Vulnerable Software and Affected Versions**
Booking for Appointments and Events Calendar – Amelia versions prior to 2.4.4
**Description**
An issue exists in the Customer Import feature where insufficient escaping of user-supplied parameters and a lack of proper preparation of SQL queries allow for SQL Injection. This enables authenticated attackers with the `wpamelia-manager` role to append malicious SQL queries to existing ones, potentially leading to the extraction of sensitive information from the database.
**Recommendations**
Update the plugin to version 2.4.4 or later.