SQL Injection Vulnerability in Booking for Appointments and Events Calendar Plugin by WordPress
CVE-2026-4668

6.5MEDIUM

What is CVE-2026-4668?

The Amelia plugin for WordPress suffers from an SQL Injection vulnerability due to insufficient escaping of the sort parameter in its payments listing endpoint. In all versions up to 2.1.2, the plugin allows authenticated users with Manager-level access to manipulate SQL queries by directly interpolating user-supplied values into the ORDER BY clause without proper sanitization. This vulnerability could enable attackers to exploit the database by appending additional queries, potentially gaining access to sensitive information through time-based blind SQL injection, as GET requests bypass Amelia's nonce validation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Booking for Appointments and Events Calendar – Amelia 0 <= 2.1.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Perla
.