Missing Authorization
11 records33.3%First: 2022. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 33 vulnerability records associated with Booking for Appointments and Events Calendar – Amelia, published between 2022 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2022 | 7 | |
| 2023 | 2 | |
| 2024 | 7 | |
| 2025 | 4 | |
| 2026 | 13 |
| Severity | Records | Share |
|---|---|---|
| High | 8 | 24.2% |
| Medium | 25 | 75.8% |
First: 2022. Latest: 2026.
First: 2022. Latest: 2024.
First: 2025. Latest: 2026.
First: 2024. Latest: 2026.
First: 2026. Latest: 2026.
First: 2022. Latest: 2024.
First: 2022. Latest: 2022.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
2.4.42.4.32.42.32.2.12.22.1.39.22.1.22.02.0.01.2.371.2.361.2.201.2.171.2.51.2.11.1.61.0.961.0.941.0.991.0.861.0.761.0.481.0.491.0.47Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.4.3 | Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import | July 16, 2026 | 2.4.4 | Medium |
*-2.4.2 | Booking for Appointments and Events Calendar – Amelia <= 2.4.2 - Unauthenticated SQL Injection | July 8, 2026 | 2.4.3 | High |
*-2.3 | Booking for Appointments and Events Calendar – Amelia <= 2.3 - Authenticated (Subscriber+) Privilege Escalation | June 2, 2026 | 2.4 | High |
*-2.2.1 | Booking for Appointments and Events Calendar – Amelia <= 2.2.1 - Unauthenticated Authorization Bypass via Remote Approval Endpoint | May 1, 2026 | 2.3 | Medium |
*-2.2 | Booking for Appointments and Events Calendar – Amelia <= 2.2 - Missing Authorization | April 28, 2026 | 2.2.1 | Medium |
*-2.2 | Booking for Appointments and Events Calendar – Amelia <= 2.2 - Unauthenticated Information Exposure | April 23, 2026 | 2.2.1 | Medium |
*-2.1.3 | Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter | April 6, 2026 | 2.2 | High |
*-2.1.2 | Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter | March 31, 2026 | 2.1.3 | Medium |
8.3-9.1.2 | Amelia Booking 8.3 - 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change | March 25, 2026 | 9.2 | High |
*-2.1.1 | Amelia <= 2.1.1 - Authenticated (Custom role+) SQL Injection | March 25, 2026 | 2.1.2 | Medium |
*-1.2.38 | Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Authenticated (Employee+) Privilege Escalation | March 4, 2026 | 2.0 | High |
*-1.2.38 | Amelia <= 1.2.38 - Missing Authorization | January 11, 2026 | 2.0 | Medium |
*-1.2.38 | Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions | January 8, 2026 | 2.0.0 | Medium |
1.2.18-1.2.36 | Amelia 1.2.18 - 1.2.36 - Unauthenticated Sensitive Information Exposure | November 18, 2025 | 1.2.37 | Medium |
*-1.2.35 | Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via search | November 15, 2025 | 1.2.36 | High |
*-1.2.19 | Booking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure | March 27, 2025 | 1.2.20 | Medium |
*-1.2.16 | Amelia <= 1.2.16 - Unauthenticated Insecure Direct Object Reference | February 23, 2025 | 1.2.17 | Medium |
*-1.2.4 | Booking for Appointments and Events Calendar – Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure | September 4, 2024 | 1.2.5 | Medium |
*-1.2 | Booking for Appointments and Events Calendar – Amelia <= 1.2 - Unauthenticated Full Path Disclosure | August 7, 2024 | 1.2.1 | Medium |
*-1.1.5 | Amelia <= 1.1.5 & Amelia (Pro) <= 7.5.1 - Authenticated (Admin+) Stored Cross-Site Scripting | June 20, 2024 | 1.1.6 | Medium |
*-1.0.95 | Amelia <= 1.0.95 - Cross-Site Request Forgery | April 10, 2024 | 1.0.96 | Medium |
*-1.0.98 | Booking for Appointments and Events Calendar – Amelia <= 1.0.98 - Reflected Cross-Site Scripting | February 29, 2024 | 1.0.99 | Medium |
*-1.0.93 | Booking for Appointments and Events Calendar – Amelia <= 1.0.93 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode | January 18, 2024 | 1.0.94 | Medium |
*-1.0.98 | Amelia <= 1.0.98 - Missing Authorization | January 17, 2024 | 1.0.99 | Medium |
*-1.0.85 | Booking for Appointments and Events Calendar – Amelia <= 1.0.85 - Stored Cross-Site Scripting via Shortcode | December 22, 2023 | 1.0.86 | Medium |
Selected source records
Published: July 16, 2026
Published: July 8, 2026
Published: June 2, 2026
Published: May 1, 2026
Published: April 28, 2026
Published: April 23, 2026
Published: April 6, 2026
Published: March 31, 2026
Published: March 4, 2026
Published: June 2, 2026
Published: March 25, 2026
Published: April 6, 2026
Published: February 23, 2022
Published: July 8, 2026
Published: November 15, 2025
Published: March 2, 2022
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.