Impact
The Amelia plugin accepts user input through a rich‑text editor. This vulnerability allows malicious database queries. Successful exploitation can lead to extraction, modification, or deletion of data stored by the plugin, which may contain sensitive booking information. The flaw is a classic SQL injection described by CWE‑89. At minimum, an attacker could read or alter the database; if the underlying database connection is elevated, the impact could expand to full database compromise.
Affected Systems
The flaw affects the Amelia booking plugin for WordPress, versions 2.4.9 and earlier, WordPress sites running these versions of the plugin are vulnerable.
Risk and Exploitability
The CVSS base score of 7.6 indicates high severity. The EPSS score is <1%, indicating a very low exploitation probability. An attacker can send a crafted request to the plugin’s editor endpoint from any internet‑accessible WordPress instance; if the attacker can authenticate or trick an administrator into using the editor, the injection can be executed. A patch is available (upgrade to version 2.4.10 or newer); without patch the vulnerability remains fully exploitable.
OpenCVE Enrichment