Stored Cross-Site Scripting Vulnerability in Amelia Plugin for WordPress
CVE-2026-6286

7.2HIGH

What is CVE-2026-6286?

The Amelia plugin for WordPress is susceptible to Stored Cross-Site Scripting due to an authentication bypass in versions up to 2.2. This vulnerability arises when the plugin inadequately verifies nonce tokens, allowing unauthorized users to submit potentially malicious booking data. Despite applying text sanitation to customer name fields, the plugin retains special characters such as double quotes, enabling attackers to inject harmful scripts. The exploit activates in the administrative Calendar view, where an event's content can execute harmful JavaScript upon interaction. This poses a significant risk, as it could allow an attacker to execute arbitrary scripts, jeopardizing the site’s security when an administrator accesses a compromised appointment.

Affected Version(s)

Booking for Appointments and Events Calendar – Amelia 0 <= 2.2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucas Montes (NiRoX)
.