Impact
The Amelia WordPress plugin suffered from missing capability checks on several AJAX endpoints, allowing attackers who are not logged in to perform privileged operations. An unauthenticated user can trigger actions such as marking payments as refunded, sending queued notifications via email, SMS or WhatsApp, and retrieving debug information. This flaw enables manipulation of financial records, potential revenue loss, and unauthorized access to sensitive debugging data, undermining both integrity and confidentiality of the booking system.
Affected Systems
All released versions of the Amelia Booking for Appointments and Events Calendar plugin up to and including version 1.2.38 are affected. The vulnerability is specific to this WordPress plugin and does not impact other products or non‑WordPress systems.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity, while the EPSS score of less than 1 % indicates a low current probability of exploitation. The flaw is not yet listed in CISA’s KEV catalog. Attackers can exploit the vulnerability by sending unauthenticated AJAX requests directly to the vulnerable endpoints. No special access or privileges are required beyond the ability to reach the WordPress site.
OpenCVE Enrichment