CVE-2024-6225: Amelia <= 1.1.5 & Amelia (Pro) <= 7.5.1 - Authenticated (Admin+) Stored Cross-Site Scripting
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.5 (and 7.5.1 for the Pro version) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfilteredhtml has been disabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Amelia (Booking for Appointments and Events Calendar)to a version that resolves this vulnerability.Fixed in 1.1.5 - Upgrade
Upgrade
WordPress plugin: Amelia (Pro) (Booking for Appointments and Events Calendar)to a version that resolves this vulnerability.Fixed in 7.5.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6225?
CVE-2024-6225 is classified as a moderate severity vulnerability that allows stored cross-site scripting.
How do I fix CVE-2024-6225?
To resolve CVE-2024-6225, update the Booking for Appointments and Events Calendar – Amelia plugin to version 1.1.6 or later.
Which versions of the Amelia plugin are affected by CVE-2024-6225?
CVE-2024-6225 affects all versions of the Amelia plugin up to and including version 1.1.5 and version 7.5.1 for the Pro version.
What kind of attack does CVE-2024-6225 enable?
CVE-2024-6225 enables attackers to execute stored cross-site scripting (XSS) attacks through vulnerable admin settings.
How can I identify if my website is vulnerable to CVE-2024-6225?
You can identify vulnerability to CVE-2024-6225 by checking if you are using the affected versions of the Amelia plugin prior to the fix.