Back to Blog
Insights

Amelia Booking Reflected XSS: CVE Analysis & Fix

Amelia Booking Reflected XSS: CVE Analysis & Fix

As part of our ongoing commitment to making the internet safer, Ikzero actively participates in responsible vulnerability disclosure programs. In early 2024, our Principal Consultant, Muhammad Hassham Nagori, discovered a reflected cross-site scripting (XSS) vulnerability in Amelia, the popular Booking for Appointments and Events Calendar WordPress plugin, used on over 40,000 websites.

CVE-2024-1484 is a medium-severity reflected cross-site scripting flaw (CVSS 6.1) in Amelia versions up to 1.0.98, a WordPress booking plugin used on over 40,000 websites, fixed by the vendor in version 1.0.99.

Vulnerability Summary

Plugin Amelia: Booking for Appointments and Events Calendar (by TMS)

Vulnerability Reflected Cross-Site Scripting (XSS)

CVE CVE-2024-1484

Affected Versions Up to and including 1.0.98

Patched Version 1.0.99

Severity Medium (CVSS 6.1)

Discovered By Muhammad Hassham Nagori (Principal Consultant, Ikzero)

Technical Analysis

Our Principal Consultant found that several date parameters in the plugin were not properly sanitised on input nor escaped on output. This allowed an attacker to craft a malicious link containing a JavaScript payload that would be reflected back and executed in the victim's browser when they opened the link.

Unlike an unauthenticated SQL injection, a reflected XSS requires a victim to click a crafted link, but the consequences, especially when that victim is a logged-in administrator, are serious.

Impact Assessment

  • Session hijacking: An injected script can steal session cookies or tokens

  • Actions on behalf of an admin: Malicious requests executed with the victim's privileges

  • Credential phishing: Injected content can overlay convincing fake login prompts

  • Defacement and redirection: Visitors silently redirected to attacker-controlled pages

Responsible Disclosure Timeline

  • Discovery: Reflected XSS identified by our Principal Consultant during security research

  • Disclosure: Responsibly reported to the vendor through a coordinated program

  • Vendor Response: TMS acknowledged the report and prepared a fix

  • Patch Released: Version 1.0.99 resolved the input-sanitisation and output-escaping gaps

Lessons for Website Owners

  • Escape everything on output: Most XSS bugs come down to trusting user-controlled input in the page

  • Update plugins promptly: 1.0.99 closed the gap; unpatched sites remained exposed

  • Beware "harmless" parameters: Date fields are easy to overlook, yet were the entry point here

  • Add a Content Security Policy: A strong CSP significantly limits the impact of reflected XSS

  • Test manually: Context-aware XSS is frequently missed by automated scanners

Why This Matters for Your Business

When you work with Ikzero, you are working with a team that actively discovers vulnerabilities in production software trusted by tens of thousands of businesses. We bring that same offensive rigour to every penetration test and secure website we build.

Is Your Web Application Secure?

Vulnerabilities like this could be lurking in your stack right now. Schedule a free security consultation with our team today, or see our secure web development service.

Reference: WPScan: Amelia < 1.0.99 Reflected Cross-Site Scripting (CVE-2024-1484)

Get Started

Want a security-first build?

Get a free security review. We'll look at where you stand today and tell you what to fix first, no strings attached.

Talk to an Expert
Amelia Booking Reflected XSS: CVE Analysis & Fix - IKZERO