Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Booking for Appointments and Events Calendar – Amelia Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 33 vulnerability records associated with Booking for Appointments and Events Calendar – Amelia, published between 2022 and 2026.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

33Total records
0Critical
8High
25Medium
0Low
0Informational
33Patched records
0Currently marked unpatched
2022-02-23First disclosure
2026-07-16Latest disclosure
33 of 33CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202277 records
202322 records
202477 records
202544 records
20261313 records

Severity Breakdown

SeverityRecordsShare
High824.2%
Medium2575.8%

Vulnerability-Type Breakdown

Missing Authorization

11 records33.3%

First: 2022. Latest: 2026.

Cross-Site Scripting

7 records21.2%

First: 2022. Latest: 2024.

SQL Injection

5 records15.2%

First: 2025. Latest: 2026.

Information Disclosure

4 records12.1%

First: 2024. Latest: 2026.

Privilege Escalation

3 records9.1%

First: 2026. Latest: 2026.

CSRF

2 records6.1%

First: 2022. Latest: 2024.

Arbitrary File Upload

1 record3%

First: 2022. Latest: 2022.

Patch Status

Patched
33
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 2.4.4
  • 2.4.3
  • 2.4
  • 2.3
  • 2.2.1
  • 2.2
  • 2.1.3
  • 9.2
  • 2.1.2
  • 2.0
  • 2.0.0
  • 1.2.37
  • 1.2.36
  • 1.2.20
  • 1.2.17
  • 1.2.5
  • 1.2.1
  • 1.1.6
  • 1.0.96
  • 1.0.94
  • 1.0.99
  • 1.0.86
  • 1.0.76
  • 1.0.48
  • 1.0.49
  • 1.0.47

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-2.4.3Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer ImportJuly 16, 20262.4.4Medium
*-2.4.2Booking for Appointments and Events Calendar – Amelia <= 2.4.2 - Unauthenticated SQL InjectionJuly 8, 20262.4.3High
*-2.3Booking for Appointments and Events Calendar – Amelia <= 2.3 - Authenticated (Subscriber+) Privilege EscalationJune 2, 20262.4High
*-2.2.1Booking for Appointments and Events Calendar – Amelia <= 2.2.1 - Unauthenticated Authorization Bypass via Remote Approval EndpointMay 1, 20262.3Medium
*-2.2Booking for Appointments and Events Calendar – Amelia <= 2.2 - Missing AuthorizationApril 28, 20262.2.1Medium
*-2.2Booking for Appointments and Events Calendar – Amelia <= 2.2 - Unauthenticated Information ExposureApril 23, 20262.2.1Medium
*-2.1.3Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' ParameterApril 6, 20262.2High
*-2.1.2Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' ParameterMarch 31, 20262.1.3Medium
8.3-9.1.2Amelia Booking 8.3 - 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password ChangeMarch 25, 20269.2High
*-2.1.1Amelia <= 2.1.1 - Authenticated (Custom role+) SQL InjectionMarch 25, 20262.1.2Medium
*-1.2.38Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Authenticated (Employee+) Privilege EscalationMarch 4, 20262.0High
*-1.2.38Amelia <= 1.2.38 - Missing AuthorizationJanuary 11, 20262.0Medium
*-1.2.38Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX ActionsJanuary 8, 20262.0.0Medium
1.2.18-1.2.36Amelia 1.2.18 - 1.2.36 - Unauthenticated Sensitive Information ExposureNovember 18, 20251.2.37Medium
*-1.2.35Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via searchNovember 15, 20251.2.36High
*-1.2.19Booking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path DisclosureMarch 27, 20251.2.20Medium
*-1.2.16Amelia <= 1.2.16 - Unauthenticated Insecure Direct Object ReferenceFebruary 23, 20251.2.17Medium
*-1.2.4Booking for Appointments and Events Calendar – Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information ExposureSeptember 4, 20241.2.5Medium
*-1.2Booking for Appointments and Events Calendar – Amelia <= 1.2 - Unauthenticated Full Path DisclosureAugust 7, 20241.2.1Medium
*-1.1.5Amelia <= 1.1.5 & Amelia (Pro) <= 7.5.1 - Authenticated (Admin+) Stored Cross-Site ScriptingJune 20, 20241.1.6Medium
*-1.0.95Amelia <= 1.0.95 - Cross-Site Request ForgeryApril 10, 20241.0.96Medium
*-1.0.98Booking for Appointments and Events Calendar – Amelia <= 1.0.98 - Reflected Cross-Site ScriptingFebruary 29, 20241.0.99Medium
*-1.0.93Booking for Appointments and Events Calendar – Amelia <= 1.0.93 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcodeJanuary 18, 20241.0.94Medium
*-1.0.98Amelia <= 1.0.98 - Missing AuthorizationJanuary 17, 20241.0.99Medium
*-1.0.85Booking for Appointments and Events Calendar – Amelia <= 1.0.85 - Stored Cross-Site Scripting via ShortcodeDecember 22, 20231.0.86Medium

Selected source records

Latest Records

MediumCVE-2026-14782

Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import

Published: July 16, 2026

Affected versions
*-2.4.3
Patched versions
2.4.4
Original Wordfence record
HighCVE-2026-57702

Booking for Appointments and Events Calendar – Amelia <= 2.4.2 - Unauthenticated SQL Injection

Published: July 8, 2026

Affected versions
*-2.4.2
Patched versions
2.4.3
Original Wordfence record
HighCVE-2026-48889

Booking for Appointments and Events Calendar – Amelia <= 2.3 - Authenticated (Subscriber+) Privilege Escalation

Published: June 2, 2026

Affected versions
*-2.3
Patched versions
2.4
Original Wordfence record
MediumCVE-2026-6449

Booking for Appointments and Events Calendar – Amelia <= 2.2.1 - Unauthenticated Authorization Bypass via Remote Approval Endpoint

Published: May 1, 2026

Affected versions
*-2.2.1
Patched versions
2.3
Original Wordfence record
MediumCVE-2026-40795

Booking for Appointments and Events Calendar – Amelia <= 2.2 - Missing Authorization

Published: April 28, 2026

Affected versions
*-2.2
Patched versions
2.2.1
Original Wordfence record
MediumCVE-2026-40789

Booking for Appointments and Events Calendar – Amelia <= 2.2 - Unauthenticated Information Exposure

Published: April 23, 2026

Affected versions
*-2.2
Patched versions
2.2.1
Original Wordfence record
HighCVE-2026-5465

Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter

Published: April 6, 2026

Affected versions
*-2.1.3
Patched versions
2.2
Original Wordfence record
MediumCVE-2026-4668

Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter

Published: March 31, 2026

Affected versions
*-2.1.2
Patched versions
2.1.3
Original Wordfence record

Highest-Severity Records

HighCVE-2026-24963

Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Authenticated (Employee+) Privilege Escalation

Published: March 4, 2026

Affected versions
*-1.2.38
Patched versions
2.0
Original Wordfence record
HighCVE-2026-48889

Booking for Appointments and Events Calendar – Amelia <= 2.3 - Authenticated (Subscriber+) Privilege Escalation

Published: June 2, 2026

Affected versions
*-2.3
Patched versions
2.4
Original Wordfence record
HighCVE-2026-2931

Amelia Booking 8.3 - 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change

Published: March 25, 2026

Affected versions
8.3-9.1.2
Patched versions
9.2
Original Wordfence record
HighCVE-2026-5465

Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter

Published: April 6, 2026

Affected versions
*-2.1.3
Patched versions
2.2
Original Wordfence record
HighCVE-2022-0687

Appointment and Event Booking Calendar - Amelia < 1.0.47 - Arbitrary File Upload

Published: February 23, 2022

Affected versions
[*, 1.0.47)
Patched versions
1.0.47
Original Wordfence record
HighCVE-2026-57702

Booking for Appointments and Events Calendar – Amelia <= 2.4.2 - Unauthenticated SQL Injection

Published: July 8, 2026

Affected versions
*-2.4.2
Patched versions
2.4.3
Original Wordfence record
HighCVE-2025-12482

Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via search

Published: November 15, 2025

Affected versions
*-1.2.35
Patched versions
1.2.36
Original Wordfence record
HighCVE-2022-0834

Amelia <= 1.0.46 - Stored Cross Site Scripting via lastName

Published: March 2, 2022

Affected versions
*-1.0.46
Patched versions
1.0.47
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory