CVE-2026-14213: Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14213?
CVE-2026-14213 has a risk rating of 45, indicating a significant vulnerability.
How do I fix CVE-2026-14213?
To remediate CVE-2026-14213, update the Booking for Appointments and Events Calendar plugin to version 2.4.6 or later.
What type of vulnerability is CVE-2026-14213?
CVE-2026-14213 is an IDOR (Insecure Direct Object Reference) vulnerability that allows unauthorized access to customer data.
Who is affected by CVE-2026-14213?
Any WordPress site using the Booking for Appointments and Events Calendar plugin version prior to 2.4.6 is affected by CVE-2026-14213.
What can attackers do with CVE-2026-14213?
Attackers can exploit CVE-2026-14213 to access and disclose customers' personal data by manipulating appointment identifiers.