SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14214

LOW · CVSS 2.7 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The Booking for Appointments and Events Calendar WordPress plugin prior to version 2.4.4 is vulnerable due to inadequate restrictions on fields during customer imports, enabling users with the Amelia Manager role to alter any stored user record. This could lead to unauthorized modifications of sensitive user data, posing a significant risk to user privacy and data integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-14214
Severity
LOW
CVSS
2.7
EPSS
0.16%
WordPress

Original NVD Description

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.