CVE-2022-0837
Appointment and Event Booking Calendar for WordPress – Amelia <= 1.0.47 - Information Disclosure and SMS Spam
mediumIncorrect Authorization
6.4
CVSS Score
6.4
CVSS Score
medium
Severity
1.0.48
Patched in
680d
Time to patch
Description
The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment history. A malicious actor can abuse this vulnerability to drain out the account balance by keep sending SMS notification.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NAttack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Low
Confidentiality
Low
Integrity
None
Availability
Technical Details
Affected versions
<1.0.48PublishedMarch 14, 2022
Last updatedJanuary 22, 2024
Affected pluginameliabooking
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.