Pricing
Case studies
Login
Start trial
Amelia
ameliabooking
Developer
2.1.3
Latest version
90,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
26 patched
11 Mitigation rules
Authenticated (Manager+) SQL Injection via 'sort' Parameter vulnerability
<= 2.1.2
1 day ago
Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change vulnerability
<= 9.1.2
6 days ago
Privilege Escalation vulnerability
<= 1.2.38
04/03/2026
Missing Authorization to Unauthenticated Multiple AJAX Actions vulnerability
<= 1.2.38
30/01/2026
Broken Access Control vulnerability
<= 1.2.38
11/01/2026
WordPress Amelia plugin - 1.2.18-1.2.36 - Unauthenticated Sensitive Information Exposure vulnerability
1.2.18-1.2.36
18/11/2025
Unauthenticated SQL Injection via search vulnerability
<= 1.2.35
17/11/2025
Unauthenticated Full Path Disclosure vulnerability
<= 1.2.19
27/03/2025
Insecure Direct Object References (IDOR) vulnerability
<= 1.2.16
23/02/2025
Missing Authorization to Sensitive Information Exposure vulnerability
<= 1.2.4
05/09/2024
Unauthenticated Full Path Disclosure vulnerability
<= 1.2
08/08/2024
Malicious Polyfill.io Embed vulnerability
<= 1.1.8
03/07/2024
Authenticated Stored Cross-Site Scripting vulnerability
<= 1.1.5
20/06/2024
Cross Site Request Forgery (CSRF) vulnerability
<= 1.0.95
10/04/2024
Reflected Cross-Site Scripting vulnerability
<= 1.0.98
01/03/2024
Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode vulnerability
<= 1.0.93
19/01/2024
Broken Access Control vulnerability
<= 1.0.98
17/01/2024
Cross Site Scripting (XSS) vulnerability
<= 1.0.85
22/12/2023
Cross Site Scripting (XSS) vulnerability
<= 1.0.75
06/04/2023
SMS Service Abuse and Sensitive Data Disclosure vulnerability
<= 1.0.47
14/03/2022
Arbitrary Appointments Status Update vulnerability
<= 1.0.48
14/03/2022
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 1.0.46
02/03/2022
Arbitrary Appointments Update and Sensitive Data Disclosure vulnerability
<= 1.0.46
01/03/2022
Remote Code Execution (RCE) vulnerability
<= 1.0.45
23/02/2022
Arbitrary Customer Deletion via Cross-Site Request Forgery (CSRF) vulnerability
<= 1.0.45
23/02/2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.0.45
23/02/2022