CVE-2025-12482: ameliabooking
## The Exploit An unauthenticated attacker can extract arbitrary data from the WordPress database by injecting SQL into the `search` parameter of the Amelia event booking API endpoint. ```http POST /wp-json/amelia/v1/events HTTP/1.1 Host:...
Read article →