CVE-2026-6449: Ameliabooking Booking For Appointments And Events Calendar – Amelia

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting' status. This makes it possible for unauthenticated attackers to approve any booking that is in 'waiting' status by sending a crafted request to the publicly-accessible admin-ajax endpoint.

Affected products

  • Ameliabooking Booking For Appointments And Events Calendar – Amelia: up to and including 2.1.2

Published 2026-05-02. Last modified 2026-06-17.