CVE-2026-4668: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-4668 is a SQL Injection vulnerability in the Booking for Appointments and Events Calendar – Amelia plugin for WordPress, affecting all versions up to and including 2.1.2. The flaw resides in the payments listing endpoint, where the user-supplied sort parameter is interpolated directly into an ORDER BY clause without sanitization or whitelist validation. It was published on April 1, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Wordfence).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). In PaymentRepository.php (around line 623), the sort field from user input is concatenated directly into an ORDER BY clause of an existing SQL query without sanitization or whitelist validation — a pattern that PDO prepared statements cannot protect against, since they do not parameterize column or clause names. Additionally, GET requests to the payments listing endpoint bypass Amelia's nonce validation entirely, removing a layer of CSRF-style protection. The vulnerable code path is also visible in GetPaymentsCommandHandler.php (line 59), which passes the unsanitized parameter downstream (GitHub Advisory, PaymentRepository source).

Impact

Successful exploitation allows authenticated attackers with Manager-level (wpamelia-manager) access or higher to perform time-based blind SQL injection, enabling extraction of sensitive information from the WordPress database — including user credentials, personal data, booking records, and payment details. The impact is limited to confidentiality (no integrity or availability impact), but database exposure can facilitate account takeover or further attacks if credential hashes are recovered (GitHub Advisory, Wordfence).

Exploitability

As of the time of publication, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability requires authenticated access at the Manager level or above, which limits the attack surface compared to unauthenticated flaws. The EPSS score is approximately 0.01% (3rd percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Amelia booking plugin (version ≤ 2.1.2) via HTTP response headers, plugin enumeration tools (e.g., WPScan), or public search engines.
  2. Obtain Manager credentials: Acquire a wpamelia-manager (or higher) account through phishing, credential stuffing, or social engineering, as the vulnerability requires authenticated access.
  3. Locate the payments listing endpoint: Navigate to or directly craft a GET request to the Amelia payments listing REST endpoint (e.g., /wp-admin/admin-ajax.php or the relevant REST route for payment listings).
  4. Inject malicious sort parameter: Append a time-based blind SQL injection payload to the sort parameter, such as sort=id,(SELECT SLEEP(5)), exploiting the lack of sanitization in the ORDER BY clause. Since GET requests bypass nonce validation, no CSRF token is needed.
  5. Extract data via time-based inference: Use tools like sqlmap with time-based blind technique (--technique=T) against the vulnerable endpoint to enumerate database tables, extract password hashes, user emails, or other sensitive records (GitHub Advisory, PaymentRepository source).

Indicators of compromise

  • Network: Repeated GET requests to the Amelia payments listing endpoint with unusual or encoded sort parameter values (e.g., containing SQL keywords like SLEEP, BENCHMARK, IF, SELECT, or parentheses).
  • Logs: WordPress access logs showing GET requests to the payments endpoint with sort parameters containing SQL syntax; abnormal response time patterns (e.g., consistent 5-second delays) indicative of time-based blind injection.
  • Database: Unexpected or high-volume query activity originating from the Amelia payments query path; slow query logs showing ORDER BY clauses with injected SQL fragments.
  • Application: Amelia plugin logs or WordPress debug logs showing SQL errors or unusual query structures from PaymentRepository.php.

Mitigation and workarounds

Update the Amelia plugin to a version newer than 2.1.2, which includes the patch that sanitizes the sort parameter before interpolation into the ORDER BY clause (plugin changeset). As interim mitigations: restrict Manager-level (wpamelia-manager) access to only fully trusted users; deploy a Web Application Firewall (WAF) with rules to detect and block SQL injection patterns in query parameters; and monitor database slow query logs for anomalous activity from the payments endpoint (GitHub Advisory, Wordfence).

Community reactions

The vulnerability was discovered and reported by Wordfence, which published the advisory and assigned the CVE (Wordfence). No significant broader media coverage or notable researcher commentary beyond the initial advisory has been identified at this time.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93549HIGH8.8
  • cart-rest-api-for-woocommerce
NoYesOct 04, 2026
CVE-2026-78371MEDIUM5.9
  • woo-addon-uploads
NoYesOct 05, 2026
CVE-2026-13607MEDIUM5.9
  • woo-addon-uploads
NoNoOct 05, 2026
CVE-2026-84169MEDIUM5.3
  • upi-qr-code-payment-gateway
NoNoOct 05, 2026
CVE-2026-97332MEDIUM5.3
  • user-private-files
NoYesOct 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management