CVE-2026-14216: Amelia < 2.4.7 - Unauthenticated Notification Queue Dispatch
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Booking for Appointments and Events Calendar WordPress pluginto a version that resolves this vulnerability.Fixed in 2.4.7
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated user who can reach the affected WordPress plugin's notification-queue processing functionality can trigger dispatch of pending notifications and integration callbacks.
What versions are affected?
Booking for Appointments and Events Calendar versions earlier than 2.4.7 are affected. Version 2.4.7 is identified as the fixed version.
What can an attacker do without authentication?
An attacker can force processing of the pending notification queue, causing queued notifications and integration callbacks to be dispatched.