Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Amelia
ameliabooking
Developer
1.2.37
Latest version
90,000
Installations
1 day ago
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
20 fixed
9 Mitigation rules
Unauthenticated SQL Injection via search vulnerability
<= 1.2.35
22 hours ago
Unauthenticated Full Path Disclosure vulnerability
<= 1.2.19
Mar 27, 2025
Insecure Direct Object References (IDOR) vulnerability
<= 1.2.16
Feb 23, 2025
Missing Authorization to Sensitive Information Exposure vulnerability
<= 1.2.4
Sep 5, 2024
Unauthenticated Full Path Disclosure vulnerability
<= 1.2
Aug 8, 2024
Malicious Polyfill.io Embed vulnerability
<= 1.1.8
Jul 3, 2024
Authenticated Stored Cross-Site Scripting vulnerability
<= 1.1.5
Jun 20, 2024
Cross Site Request Forgery (CSRF) vulnerability
<= 1.0.95
Apr 10, 2024
Reflected Cross-Site Scripting vulnerability
<= 1.0.98
Mar 1, 2024
Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode vulnerability
<= 1.0.93
Jan 19, 2024
Broken Access Control vulnerability
<= 1.0.98
Jan 17, 2024
Cross Site Scripting (XSS) vulnerability
<= 1.0.85
Dec 22, 2023
Cross Site Scripting (XSS) vulnerability
<= 1.0.75
Apr 6, 2023
SMS Service Abuse and Sensitive Data Disclosure vulnerability
<= 1.0.47
Mar 14, 2022
Arbitrary Appointments Status Update vulnerability
<= 1.0.48
Mar 14, 2022
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 1.0.46
Mar 2, 2022
Arbitrary Appointments Update and Sensitive Data Disclosure vulnerability
<= 1.0.46
Mar 1, 2022
Remote Code Execution (RCE) vulnerability
<= 1.0.45
Feb 23, 2022
Arbitrary Customer Deletion via Cross-Site Request Forgery (CSRF) vulnerability
<= 1.0.45
Feb 23, 2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.0.45
Feb 23, 2022