Stored Cross-Site Scripting Vulnerability in Amelia Plugin for WordPress
CVE-2026-6286
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-6286?
The Amelia plugin for WordPress is susceptible to Stored Cross-Site Scripting due to an authentication bypass in versions up to 2.2. This vulnerability arises when the plugin inadequately verifies nonce tokens, allowing unauthorized users to submit potentially malicious booking data. Despite applying text sanitation to customer name fields, the plugin retains special characters such as double quotes, enabling attackers to inject harmful scripts. The exploit activates in the administrative Calendar view, where an event's content can execute harmful JavaScript upon interaction. This poses a significant risk, as it could allow an attacker to execute arbitrary scripts, jeopardizing the site’s security when an administrator accesses a compromised appointment.
Affected Version(s)
Booking for Appointments and Events Calendar – Amelia 0 <= 2.2