PT-2026-82880 · WordPress · Amelia

·

CVE-2026-6286

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Amelia plugin for WordPress versions prior to 2.3
Description An authentication bypass occurs because the AddBookingCommand function in Command.php skips nonce verification, allowing unauthenticated users to submit booking data. Although the firstName and lastName variables are processed by sanitize text field(), this function preserves double quotes. In the administrative Calendar view, the eventContent callback in redesign/dist/index.js interpolates these names into JavaScript template literals and renders them via innerHTML without proper HTML entity encoding. This allows an unauthenticated attacker to inject arbitrary web scripts through the customer name fields that execute when an administrator hovers over the malicious appointment on the Calendar page.
Recommendations Update the plugin to a version later than 2.2.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6286

Affected Products

Amelia