{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/tms-outsource/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-6286"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Amelia"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress","vulnerability"],"_cs_type":"advisory","_cs_vendors":["TMS Outsource"],"content_html":"\u003cp\u003eThe Booking for Appointments and Events Calendar (Amelia) plugin for WordPress (versions 2.2 and below) is vulnerable to Stored Cross-Site Scripting (XSS) due to an authentication bypass in the plugin's command processing. The AddBookingCommand class fails to perform nonce verification, allowing unauthenticated users to submit booking data. Although the plugin applies sanitize_text_field() to firstName and lastName parameters, this function does not remove double quotes.\u003c/p\u003e\n\u003cp\u003eThe vulnerability is triggered when the application renders the customer name in the administrative Calendar view. The plugin utilizes a FullCalendar eventContent callback that interpolates these names directly into JavaScript template literals and renders them via innerHTML without HTML entity encoding. By breaking out of the JavaScript context using a double quote, an attacker can inject arbitrary JavaScript event handlers. This results in the execution of malicious scripts within the browser session of an administrator who views the compromised event in the WordPress dashboard.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site with the Amelia plugin (v2.2 or lower).\u003c/li\u003e\n\u003cli\u003eAttacker probes the appointment booking API to locate the AddBookingCommand endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious booking request containing an XSS payload (e.g., '\u0026quot; onmouseover=\u0026quot;alert(document.cookie)\u0026quot;') in the customer firstName field.\u003c/li\u003e\n\u003cli\u003eAttacker sends the POST request to the endpoint, bypassing nonce verification due to the flaw in Command.php.\u003c/li\u003e\n\u003cli\u003eThe plugin saves the malicious string to the database via BookingApplicationService.php.\u003c/li\u003e\n\u003cli\u003eA privileged administrator navigates to the Amelia Calendar page in the WordPress dashboard.\u003c/li\u003e\n\u003cli\u003eThe Calendar page retrieves the malicious booking data and renders it unsafely via innerHTML in the browser.\u003c/li\u003e\n\u003cli\u003eThe administrator's browser executes the injected JavaScript upon interacting with the event.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary JavaScript execution within an administrative session. This enables attackers to perform unauthorized actions on behalf of the administrator, such as creating new rogue accounts, modifying plugin settings, or stealing administrative session cookies to facilitate account takeover. The impact is significant for organizations relying on the Amelia plugin to manage external-facing appointment workflows.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately update the Amelia plugin to a version patched against CVE-2026-6286.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect POST requests directed to the WordPress admin API, specifically monitoring for unusual characters like double quotes or JavaScript event handlers in booking parameters.\u003c/li\u003e\n\u003cli\u003eRestrict access to the WordPress administrative dashboard to known-trusted IP addresses to reduce the likelihood of an administrator interacting with malicious payloads.\u003c/li\u003e\n\u003cli\u003eMonitor WordPress access logs for high volumes of POST requests to booking endpoints from single IP addresses, which may indicate automated booking abuse.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-28T09:13:21Z","date_published":"2026-08-28T09:13:21Z","id":"https://feed.craftedsignal.io/briefs/2026-08-amelia-xss/","summary":"An unauthenticated stored Cross-Site Scripting (XSS) vulnerability in the Amelia WordPress plugin allows attackers to inject malicious scripts into appointment bookings, which execute in an administrator's browser context.","title":"Stored XSS via Authentication Bypass in Amelia WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-amelia-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - TMS Outsource","version":"https://jsonfeed.org/version/1.1"}