CVE-2024-6552 affects the Booking for Appointments and Events Calendar – Amelia plugin for WordPress, specifically all versions up to and including 1.2. It is a Full Path Disclosure vulnerability stemming from the plugin's use of Symfony with display_errors enabled in test files. This allows unauthenticated attackers to retrieve the web application's full path, which has a CVSS score of 5.3 (Medium) due to its low impact on confidentiality and lack of integrity or availability impact. While the disclosed information isn't harmful on its own, it can aid in other attacks. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Ameliabooking | Booking For Appointments And Events Calendar – Amelia | >= 0, <= 1.2CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.