The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 28 Mar 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website. | |
Title | Booking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure | |
Weaknesses | CWE-200 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-03-28T07:33:04.467Z
Updated: 2025-03-28T14:35:39.786Z
Reserved: 2025-03-20T21:38:51.642Z
Link: CVE-2025-2578

Updated: 2025-03-28T14:35:35.299Z

Status : Awaiting Analysis
Published: 2025-03-28T08:15:15.603
Modified: 2025-03-28T18:11:40.180
Link: CVE-2025-2578

No data.