CVE Database /
CVE-2026-14214
CVE
CVE-2026-14214 — Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-14214
|
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.4 |
Improper Authentication |
Unknown
|
< 2.4.4
|
2.4.4 |
2026-08-01 |
—
|
CVE-2026-14214
A vulnerability exists in the Booking for Appointments and Events Calendar plugin prior to version 2.4.4, where an unauthorized modification can be made to user records through its customer import feature. Specifically, a user with the Amelia Manager role can manipulate arbitrary columns of stored user data by including them in the import request.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings