
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4668 is a SQL Injection vulnerability in the Booking for Appointments and Events Calendar – Amelia plugin for WordPress, affecting all versions up to and including 2.1.2. The flaw resides in the payments listing endpoint, where the user-supplied sort parameter is interpolated directly into an ORDER BY clause without sanitization or whitelist validation. It was published on April 1, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Wordfence).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). In PaymentRepository.php (around line 623), the sort field from user input is concatenated directly into an ORDER BY clause of an existing SQL query without sanitization or whitelist validation — a pattern that PDO prepared statements cannot protect against, since they do not parameterize column or clause names. Additionally, GET requests to the payments listing endpoint bypass Amelia's nonce validation entirely, removing a layer of CSRF-style protection. The vulnerable code path is also visible in GetPaymentsCommandHandler.php (line 59), which passes the unsanitized parameter downstream (GitHub Advisory, PaymentRepository source).
Successful exploitation allows authenticated attackers with Manager-level (wpamelia-manager) access or higher to perform time-based blind SQL injection, enabling extraction of sensitive information from the WordPress database — including user credentials, personal data, booking records, and payment details. The impact is limited to confidentiality (no integrity or availability impact), but database exposure can facilitate account takeover or further attacks if credential hashes are recovered (GitHub Advisory, Wordfence).
As of the time of publication, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability requires authenticated access at the Manager level or above, which limits the attack surface compared to unauthenticated flaws. The EPSS score is approximately 0.01% (3rd percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
wpamelia-manager (or higher) account through phishing, credential stuffing, or social engineering, as the vulnerability requires authenticated access./wp-admin/admin-ajax.php or the relevant REST route for payment listings).sort parameter: Append a time-based blind SQL injection payload to the sort parameter, such as sort=id,(SELECT SLEEP(5)), exploiting the lack of sanitization in the ORDER BY clause. Since GET requests bypass nonce validation, no CSRF token is needed.sqlmap with time-based blind technique (--technique=T) against the vulnerable endpoint to enumerate database tables, extract password hashes, user emails, or other sensitive records (GitHub Advisory, PaymentRepository source).sort parameter values (e.g., containing SQL keywords like SLEEP, BENCHMARK, IF, SELECT, or parentheses).sort parameters containing SQL syntax; abnormal response time patterns (e.g., consistent 5-second delays) indicative of time-based blind injection.PaymentRepository.php.Update the Amelia plugin to a version newer than 2.1.2, which includes the patch that sanitizes the sort parameter before interpolation into the ORDER BY clause (plugin changeset). As interim mitigations: restrict Manager-level (wpamelia-manager) access to only fully trusted users; deploy a Web Application Firewall (WAF) with rules to detect and block SQL injection patterns in query parameters; and monitor database slow query logs for anomalous activity from the payments endpoint (GitHub Advisory, Wordfence).
The vulnerability was discovered and reported by Wordfence, which published the advisory and assigned the CVE (Wordfence). No significant broader media coverage or notable researcher commentary beyond the initial advisory has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."