CVE-2026-14211: Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14211?
The severity of CVE-2026-14211 is classified as 65, indicating a moderate risk of data disclosure and modification.
How do I fix CVE-2026-14211?
To fix CVE-2026-14211, update the Amelia Pro plugin to version 9.7 or later, which includes the necessary security improvements.
What type of vulnerability is CVE-2026-14211?
CVE-2026-14211 is an IDOR vulnerability that allows unauthorized access to customer data by authenticated employees.
Who is affected by CVE-2026-14211?
Anyone using the Booking for Appointments and Events Calendar WordPress plugin prior to version 9.7 is affected by CVE-2026-14211.
What are the consequences of CVE-2026-14211?
The consequences of CVE-2026-14211 can include unauthorized access, disclosure, and modification of personal customer data.