WordPress security by component
Booking for Appointments and Events Calendar
Plugin description
Booking for Appointments and Events Calendar is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
booking-for-appointments-and-events-calendarLatest vulnerability
CVE-2026-14214: Amelia Manager imports can overwrite arbitrary user-record columns
Booking for Appointments and Events Calendar before 2.4.4 does not restrict which database fields its customer import may write. A user holding the plugin's Amelia Manager role can target any stored user record and supply arbitrary column names and values in the import request, modifying fields beyond legitimate customer data. The record does not disclose the import endpoint, target-user parameter, accepted column syntax or update function, so whether a particular field yields further privilege escalation remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-14214
Amelia Manager imports can overwrite arbitrary user-record columns
Booking for Appointments and Events Calendar before 2.4.4 does not restrict which database fields its customer import may write. A user holding the plugin's Amelia Manager role can target any stored user record and supply arbitrary column names and values in the import request, modifying fields beyond legitimate customer data. The record does not disclose the import endpoint, target-user parameter, accepted column syntax or update function, so whether a particular field yields further privilege escalation remains unknown.
|
2.4.4 |
CVEPending
NVDPending
|