CVE-2026-62112
moderateSQL Injection in Amelia WordPress Booking Plugin (≤ 2.4.9)
CVE-2026-62112 is an SQL injection (CWE-89) in the Amelia booking plugin for WordPress, affecting all versions up to and including 2.4.9. It is described as an 'Editor' SQL injection, and the CVSS vector indicates the attack requires a highly privileged authenticated user (PR:H) over the network with no user interaction. A successful injection could expose sensitive data from the site's database (confidentiality impact rated high), with limited availability impact. Any WordPress site running Amelia at or below version 2.4.9 is affected. Exploitation is not currently known: the flaw is not in CISA's KEV and no public proof-of-concept exists; the issue was identified by Patchstack's audit team.
What to do: Update Amelia to the latest available release (any version newer than 2.4.9). Until patched, limit and audit high-privilege accounts (administrators/editors) on sites running Amelia, and review logs for anomalous database queries. No public exploit exists yet, but monitor vendor and Patchstack advisories for the fixed version and any emerging PoCs.
| TMS Plugins Amelia (WordPress booking plugin) | <= 2.4.9 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Editor SQL Injection in Amelia <= 2.4.9 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.