Impact
The Amelia booking plugin contains a blind SQL injection flaw that stems from improper handling of special characters in an SQL query. An attacker who can supply crafted input to the plugin can cause unfiltered SQL to be executed, permitting execution of arbitrary statements against the site’s database. The resulting loss of confidentiality and integrity could expose user credentials, booking details, or other sensitive data, and may allow deletion or alteration of stored records.
Affected Systems
WordPress sites running any version of the Amelia plugin from Melograno Venture Studio up to and including 2.4.2 are vulnerable. Both the legacy and current releases contain the same flaw, as the issue is present in all iterations through version 2.4.2 without a corresponding fix.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, while an EPSS score of less than 1% suggests a low but non-zero chance of exploitation. The vulnerability is not listed in CISA KEV. Attackers are likely to reach the flaw via the plugin’s web interface or API endpoints that accept user‑supplied data, performing blind injection to extract data or issue destructive commands. Successful exploitation could lead to data compromise or database takeover.
OpenCVE Enrichment