CVE

CVE-2026-14211 — Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 9.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-14211 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 9.7 Authorization Bypass Through User-Controlled Key Unknown < 9.7 9.7 2026-08-10

CVE-2026-14211

A vulnerability in the Booking for Appointments and Events Calendar plugin affects versions prior to 9.7, where it fails to ensure that a staff member's access is limited to their own customers' records, thereby enabling unauthorized employees with an Employee Panel login to view and alter sensitive customer information by exploiting sequential identifier enumeration.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.