WordPress security changelog
UNKNOWN CVE-2026-14214 Received

Amelia Manager imports can overwrite arbitrary user-record columns

Booking for Appointments and Events Calendar before 2.4.4 does not restrict which database fields its customer import may write. A user holding the plugin's Amelia Manager role can target any stored user record and supply arbitrary column names and values in the import request, modifying fields beyond legitimate customer data. The record does not disclose the import endpoint, target-user parameter, accepted column syntax or update function, so whether a particular field yields further privilege escalation remains unknown.

CVE / CNA score Pending The CVE record has not published a CNA CVSS assessment.
NVD score Pending NVD has not published its own CVSS assessment.
Component
Booking for Appointments and Events Calendar
Plugin slug
booking-for-appointments-and-events-calendar
Affected
< 2.4.4
Safe version
2.4.4
Published
Aug 01, 2026
Weakness
Not assigned

This CVE was published Aug 01, 2026 and is one of 1 known issue for this plugin.

Update, patch or deactivate.

Update Booking for Appointments and Events Calendar to 2.4.4 or later. Review Amelia Manager accounts and customer-import activity, compare user records with trusted data, restore unauthorized field changes, and reset credentials or roles if authentication-related columns were affected.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.

Primary and upstream sources