ZeroHour

CVE-2026-62112

moderate

SQL Injection in Amelia WordPress Booking Plugin (≤ 2.4.9)

CVSS 3.1
7.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-62112 is an SQL injection (CWE-89) in the Amelia booking plugin for WordPress, affecting all versions up to and including 2.4.9. It is described as an 'Editor' SQL injection, and the CVSS vector indicates the attack requires a highly privileged authenticated user (PR:H) over the network with no user interaction. A successful injection could expose sensitive data from the site's database (confidentiality impact rated high), with limited availability impact. Any WordPress site running Amelia at or below version 2.4.9 is affected. Exploitation is not currently known: the flaw is not in CISA's KEV and no public proof-of-concept exists; the issue was identified by Patchstack's audit team.

What to do: Update Amelia to the latest available release (any version newer than 2.4.9). Until patched, limit and audit high-privilege accounts (administrators/editors) on sites running Amelia, and review logs for anomalous database queries. No public exploit exists yet, but monitor vendor and Patchstack advisories for the fixed version and any emerging PoCs.

Affected
TMS Plugins Amelia (WordPress booking plugin)<= 2.4.9
Estimated exposure
moderatetens of thousands of sites (free Amelia version shows roughly 30k+ active installs on WordPress.org, plus an unquantified number of premium installations) — Based on the free version's public active-install count on WordPress.org (~30k+) plus a larger but unmeasured premium install base, total deployments are plausibly in the tens of thousands; note only high-privilege accounts (per CVSS PR:H)…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Editor SQL Injection in Amelia <= 2.4.9 versions.

Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.