Impact
The Amelia booking and events calendar plugin for WordPress contains a stored cross‑site scripting flaw that is triggered through the "load_manually" parameter in several Elementor widgets. Insufficient input sanitization and output escaping allow an authenticated user with Contributor or higher privileges to embed arbitrary JavaScript in the widget configuration. When a page containing the widget is viewed, the injected script runs in the browsers of all visitors, enabling session of malware. The weakness matches CWE‑79, an input validation error.
Affected Systems
All WordPress sites that have the Amelia booking plugin installed, with a version of 2.4.9 or earlier, are affected. A partial patch was introduced in 2.4.8, but the remainder of the code remains vulnerable until a version newer than 2.4.9 is deployed.
Risk and Exploitability
The CVSS score of 6.4 classifies the vulnerability as moderate severity, and no EPSS data is available, indicating that exploitation is not currently common. The flaw is not listed in the CISA KEV catalog, further suggesting limited observed exploitation. Adversaries only need Contributor‑level access—a role that is widespread on many WordPress sites—to create or edit a page that uses the vulnerable widget. Once the script is stored, it will execute for any visitor that accesses the affected page, making the impact broad and the attack path straightforward for authenticated users.
OpenCVE Enrichment