Impact
The Booking for Appointments and Events Calendar WordPress plugin (often referred to as Amelia) before version 2.4.7 processes any pending notification queue without checking if the caller is authenticated. This flaw permits any user that can reach the site to cause the queued notifications and any associated integration callbacks to be dispatched, potentially leading to unsolicited email spam, unwanted contact with third‑party services, or leakage of sensitive information carried by the notifications.
Affected Systems
WordPress sites that run the Amelia plugin in any version older than 2.4.7 are affected. Those sites typically host public‑facing appointment or event scheduling interfaces where the plugin’s notification system triggers email alerts or external integrations.
Risk and Exploitability
The CVSS score is missing from the provided data, but the vulnerability requires no authentication and can be triggered by a simple HTTP request from any remote host with network access to the site. EPSS is not reported and the issue is not listed in the CISA KEV catalog, indicating no current widespread exploitation yet. Nevertheless, the risk is moderate to high because the flaw enables high‑volume notification dispatch, which can be abused for spam, denial of service to participants, or unintended data exposure through callbacks.
OpenCVE Enrichment