WordPress · Amelia · CVE-2026-16582
**Name of the Vulnerable Software and Affected Versions**
Booking for Appointments and Events Calendar – Amelia versions prior to 2.4.6
**Description**
The plugin allows unauthenticated attackers to create approved appointment bookings without completing payment. This occurs because the software accepts a client-supplied package-redemption identifier as proof of payment without proper validation, leading to unauthorized modification of data.
**Recommendations**
Update the plugin to version 2.4.6 or later.