CVE-2026-62112: WordPress Amelia plugin <= 2.4.9 - SQL Injection vulnerability
Published Sep 11, 2026
·Updated
Editor SQL Injection in Amelia <= 2.4.9 versions.
Affected Software
1 affected component
WordPress Amelia plugin<=2.4.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Amelia Pluginto a version that resolves this vulnerability.Fixed in 2.4.10
Event History
Sep 11, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who needs to be authenticated to exploit this issue?
An attacker needs Editor-level privileges. The issue is therefore most relevant where Editor accounts are assigned to untrusted or compromised users.
2
What versions are affected?
Amelia plugin versions 2.4.9 and earlier are affected, based on the available information.
3
What security impact could successful exploitation have?
The supplied vector indicates network-reachable exploitation with low attack complexity, no user interaction, high confidentiality impact, no integrity impact, and low availability impact. The scope is changed.