Booking for Appointments and Events Calendar – Amelia <= 2.2.1 - Unauthenticated Authorization Bypass via Remote Approval Endpoint
Strategic Overview
- Status
- Patched in 2.3
- Affected Plugin
- Booking for Appointments and Events Calendar – Amelia
- Affected Version
<= 2.2.1- CVSS
- 5.3Medium
- Weakness type
- CWE-285 · Improper Authorization
- CVE
CVE-2026-6449
At a glance
CVE-2026-6449 is a medium-severity Improper Authorization vulnerability in the Booking for Appointments and Events Calendar WordPress plugin, affecting versions <= 2.2.1. It carries a CVSS score of 5.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 2.3; sites on affected versions should update now. Disclosed May 2026, reported by awhacken.
Vulnerability Overview
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.2.1. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting' status. This makes it possible for unauthenticated attackers to approve any booking that is in 'waiting' status by sending a crafted request to the publicly-accessible admin-ajax endpoint.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.
CWE-285: Improper Authorization
Booking for Appointments and Events Calendar <= 2.2.1 carries this weakness at waiting, and reaching it takes no account at all. Improper authorization means a permission check exists but does not cover the case being exercised, so a caller who is allowed to do one thing is allowed to do a neighbouring thing as well.
A lower-privileged account performs an action reserved for a higher one, which on a multi-author or membership site means an ordinary user reaching administrative behaviour. For Booking for Appointments and Events Calendar the fix is 2.3: builds <= 2.2.1 are affected, anything from 2.3 onward is not.
Remediation
Update to version 2.3, or a newer patched version
How does WordSec protect against this?
This one needs no account at all, which puts it outside what login hardening can reach; WordSec's login security narrows the account-level paths around it, and the firewall is what inspects the request itself. None of that substitutes for the fix: Booking for Appointments and Events Calendar 2.3 closes this, and updating the plugin is the step that ends it.
- Login Security
- Alerts
External References
Related records
Other vulnerabilities in Booking for Appointments and Events Calendar – Amelia
- 8.8CVE-2026-48889: Booking for Appointments… Privilege Escalation
CVE-2026-48889 - 8.8CVE-2026-5465: Amelia IDOR
CVE-2026-5465 - 8.8CVE-2026-2931: Amelia Booking 8.3 - 9.1.2 IDOR
CVE-2026-2931 - 8.8CVE-2026-24963: Booking for Appointments… Privilege Escalation
CVE-2026-24963 - 8.8CVE-2022-0687: Appointment and Event… Arbitrary File Upload
CVE-2022-0687 - 7.5CVE-2026-57702: Booking for Appointments and Events… SQL Injection
CVE-2026-57702 - 7.5CVE-2025-12482: Booking for Appointments and Events… SQL Injection
CVE-2025-12482 - 7.2CVE-2022-0834: Amelia <= 1.0.46 Stored Cross Site Scripting
CVE-2022-0834
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C