Impact
The Amelia plugin for WordPress accepts a client-supplied package‑redemption identifier as proof of payment without validating it. An unauthenticated attacker can forge this identifier and create approved appointment bookings without completing any payment, resulting in financial loss and unauthorized use of the booking system.
Affected Systems
Versions of the Amelia booking plugin up to and including 2.4.5 are affected. The vulnerability exists in the plugin’s package‑redemption handling logic and can be triggered by any user who can access the public booking interface on a WordPress site that has the plugin installed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% shows a low, though non‑zero, likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack can be performed remotely through the public booking web interface without authentication, allowing attackers to successively create paid bookings in a blind‑fold fashion. While the initial impact is limited to the compromised site, repeated exploitation could lead to significant revenue damage to the site operator.
OpenCVE Enrichment