CVE-2026-14214
N/A
N/A
Summary
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Booking for Appointments and Events Calendar | 0 < 2.4.4 | affected |
Weaknesses
- CWE-287 Improper Authentication
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.