SQL Injection Vulnerability in Booking for Appointments and Events Calendar Plugin by WordPress
CVE-2026-4668
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 March 2026
What is CVE-2026-4668?
The Amelia plugin for WordPress suffers from an SQL Injection vulnerability due to insufficient escaping of the sort parameter in its payments listing endpoint. In all versions up to 2.1.2, the plugin allows authenticated users with Manager-level access to manipulate SQL queries by directly interpolating user-supplied values into the ORDER BY clause without proper sanitization. This vulnerability could enable attackers to exploit the database by appending additional queries, potentially gaining access to sensitive information through time-based blind SQL injection, as GET requests bypass Amelia's nonce validation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Booking for Appointments and Events Calendar β Amelia 0 <= 2.1.2