SQL Injection Vulnerability in Amelia Booking Plugin by Amelia
CVE-2026-39487
7.6HIGH
What is CVE-2026-39487?
The Amelia Booking plugin exhibits a vulnerability that allows for improper neutralization of special elements in an SQL command, leading to a potential exploit through Blind SQL Injection. This affects versions from n/a to 2.1.1, which could allow attackers to manipulate database queries, gaining unauthorized access to sensitive information stored within the database.
Affected Version(s)
Amelia 0 <= 2.1.1