Input validation vulnerability in Booking for Appointments and Events Calendar – Amelia 1.2.35

The Booking for Appointments and Events Calendar plugin for WordPress, called Amelia, can be attacked by hackers through a vulnerability called SQL Injection. This happens when the ‘search’ feature is used. The plugin’s code doesn’t protect against this type of attack, which means that outsiders can add their own code to the existing code and access private information from the website’s database.

Detected in:

Booking for Appointments and Events Calendar – Amelia open vulnerable versions: >= * <= 1.2.35

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.