Amelia Manager imports can overwrite arbitrary user-record columns
Booking for Appointments and Events Calendar before 2.4.4 does not restrict which database fields its customer import may write. A user holding the plugin's Amelia Manager role can target any stored user record and supply arbitrary column names and values in the import request, modifying fields beyond legitimate customer data. The record does not disclose the import endpoint, target-user parameter, accepted column syntax or update function, so whether a particular field yields further privilege escalation remains unknown.
- Component
- Booking for Appointments and Events Calendar
- Plugin slug
booking-for-appointments-and-events-calendar- Affected
- < 2.4.4
- Safe version
2.4.4- Published
- Aug 01, 2026
- Weakness
- Not assigned
This CVE was published Aug 01, 2026 and is one of 1 known issue for this plugin.
Update, patch or deactivate.
Update Booking for Appointments and Events Calendar to 2.4.4 or later. Review Amelia Manager accounts and customer-import activity, compare user records with trusted data, restore unauthorized field changes, and reset credentials or roles if authentication-related columns were affected.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.