Impact
The Booking for Appointments and Events Calendar WordPress plugin, commonly known as Amelia, processes any pending notification queue without requiring that the caller be authenticated. The description indicates that an unauthenticated user can send a request to the endpoint responsible for dispatching queued notifications, causing the plugin to send out email alerts or trigger integration callbacks that were previously queued. Based on the description, it is inferred that this flaw can lead to unsolicited email spam, unwanted engagement with third‑party services, or inadvertent exposure of information contained in the notifications.
Affected Systems
WordPress sites that run the Amelia plugin in a version earlier than 2.4.7 are affected. These sites typically provide public appointment or event booking interfaces where the plugin’s notification system triggers email alerts or external integrations.
Risk and Exploitability
The CVSS score of 6.5 places this vulnerability in the moderate threat range, and the EPSS score is less than 1%. It is not listed in the CISA KEV catalog, indicating that widespread exploitation has not yet been observed. Nonetheless, the flaw can be exploited with a simple unauthenticated HTTP request from any remote host that can reach the site, allowing an attacker to force the dispatch of queued messages. Potential effects include a high‑volume flood of notification emails or callbacks, which could be abused for spam or to overload downstream services, and the unintended release of sensitive information carried by the notifications. The overall risk is therefore low to moderate, but the impact could be amplified if an attacker chains this with other vulnerabilities to increase spam volume or overwhelm recipients.
OpenCVE Enrichment