Unauthenticated Sensitive Data Exposure in Amelia Booking Plugin by Amelia
CVE-2026-40789
7.5HIGH
What is CVE-2026-40789?
The Amelia Booking Plugin, specifically versions up to 2.2, is susceptible to an unauthenticated sensitive data exposure vulnerability. This flaw permits unauthorized access to sensitive information, potentially compromising user data and confidentiality. It is crucial for users of the affected plugin to review and apply necessary updates or patches to mitigate the risks associated with this vulnerability.
Affected Version(s)
Amelia <= 2.2
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Weerawat Pawanawiwat (ErbaZZ) | Patchstack Bug Bounty Program