← WordPress Vulnerabilities
WordPress security by component

Booking for Appointments and Events Calendar

Booking for Appointments and Events Calendar is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: booking-for-appointments-and-events-calendar

CVE-2026-14214: Amelia Manager imports can overwrite arbitrary user-record columns

Booking for Appointments and Events Calendar before 2.4.4 does not restrict which database fields its customer import may write. A user holding the plugin's Amelia Manager role can target any stored user record and supply arbitrary column names and values in the import request, modifying fields beyond legitimate customer data. The record does not disclose the import endpoint, target-user parameter, accepted column syntax or update function, so whether a particular field yields further privilege escalation remains unknown.

PublishedAug 01, 2026
Known safe version2.4.4
Safe version
Aug 01, 2026 CVE-2026-14214
Amelia Manager imports can overwrite arbitrary user-record columns
Booking for Appointments and Events Calendar before 2.4.4 does not restrict which database fields its customer import may write. A user holding the plugin's Amelia Manager role can target any stored user record and supply arbitrary column names and values in the import request, modifying fields beyond legitimate customer data. The record does not disclose the import endpoint, target-user parameter, accepted column syntax or update function, so whether a particular field yields further privilege escalation remains unknown.
2.4.4
CVEPending
NVDPending