← Back to CVE search

CVE-2026-14214

Booking for Appointments and Events Calendar

Description

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.

CVSS 2.7EPSS 0.168%Risk 0.27
View source
Published
2026-08-01 07:16:29
Affected versions
<2.4.4
Type
Web application
Last modified
2026-08-05 17:16:40
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N