Impact
The Amelia booking and events calendar plugin for WordPress contains a stored cross‑site scripting flaw that is triggered widgets. Insufficient input sanitization and output escaping allow an authenticated user with Contributor or higher privileges to embed arbitrary JavaScript in the widget configuration. When a page containing the widget is viewed, the injected script runs in the browsers of all visitors, enabling session hijack or malware deployment. The weakness matches CWE‑79, an input validation error.
Affected Systems
All WordPress sites that have the Amelia booking plugin installed, with a version of 2.4.9 or earlier, are affected2.4.8, but the remainder of the code remains vulnerable until a version newer than 2.4.9 is deployed.
Risk and Exploitability
The CVSS score of 6.4 classifies the vulnerability as moderate severity, and the EPSS exploitation is unlikely. The flaw is not listed in the CISA KEV catalog, further suggesting limited observed exploitation. Adversaries only need Contributor‑level access—a role that is widespread on many WordPress sites—to create or edit a page that uses the vulnerable widget. Once the script is stored, it will execute for any visitor that broad and the attack path straightforward for authenticated users.
OpenCVE Enrichment