WordPress Plugin Vulnerabilities

Amelia Pro 9.0 - 9.8 - Unauthenticated Payment Bypass

Description

The plugin does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an unauthenticated attacker obtain confirmed, fully paid appointments and events without any payment being collected.

Proof of Concept

Affects Plugins

Fixed in 9.8.1

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Pedro Pinho
Submitter
Pedro Pinho
Verified
Yes

Timeline

Publicly Published
2026-09-10 (about 2 days ago)
Added
2026-09-10 (about 1 day ago)
Last Updated
2026-09-10 (about 1 day ago)

Other