Improper Authorization Vulnerability in Amelia Booking Plugin for WordPress
CVE-2026-6449
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 May 2026
What is CVE-2026-6449?
The Amelia Booking plugin for WordPress is affected by an improper authorization vulnerability present in all versions up to and including 2.1.2. This flaw arises from a logical short-circuit in the authorization logic, which allows for token validation to be bypassed if a booking holds a 'waiting' status. Consequently, this enables unauthenticated attackers to approve bookings under this status by crafting a malicious request targeting the publicly accessible admin-ajax endpoint, potentially leading to unauthorized changes in booking status.
Affected Version(s)
Booking for Appointments and Events Calendar β Amelia 0 <= 2.1.2