CVE-2022-0720: Amelia < 1.0.47 - Customer+ Arbitrary Appointments Update and Sensitive Data Disclosure
The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0720?
The severity of CVE-2022-0720 is medium with a severity value of 5.4.
How does CVE-2022-0720 affect the Amelia WordPress plugin?
CVE-2022-0720 affects the Amelia WordPress plugin version up to 1.0.47.
What is the impact of CVE-2022-0720?
The impact of CVE-2022-0720 is that any customer can update another person's booking and retrieve sensitive information about bookings.
How can I fix CVE-2022-0720?
To fix CVE-2022-0720, update the Amelia WordPress plugin to version 1.0.47 or later.
Where can I find more information about CVE-2022-0720?
You can find more information about CVE-2022-0720 at the following reference: [CVE-2022-0720](https://wpscan.com/vulnerability/435ef99c-9210-46c7-80a4-09cd4d3d00cf)