PT-2026-95132 · WordPress · Amelia
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Booking for Appointments and Events Calendar – Amelia versions prior to 2.4.6
Description
The plugin allows unauthenticated attackers to create approved appointment bookings without completing payment. This occurs because the software accepts a client-supplied package-redemption identifier as proof of payment without proper validation, leading to unauthorized modification of data.
Recommendations
Update the plugin to version 2.4.6 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amelia