CVE-2026-14311: Booking for Appointments and Events Calendar – Amelia (Premium) <= 2.4.4 - Authenticated (Custom+) Missing Authorization to Limited Account Takeover
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with wpamelia-provider role, to view and modify arbitrary customers, including password reset. Takeover of WordPress user accounts, with the roles up to Editor, is also possible if that user had made an Amelia booking. This vulnerability affects only the Premium version of the plugin, where the Employee Panel is present.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Booking for Appointments and Events Calendar – Amelia (Premium)to a version that resolves this vulnerability.Fixed in 2.4.4 - Compensating control
Because the issue allows authenticated attackers (wpamelia-provider role) to view/modify arbitrary customers (including password reset) when Employee Panel is present in the Amelia Premium plugin, restrict the wpamelia-provider role access so only trusted accounts can use it until the plugin is updated.
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must already be authenticated to WordPress with the wpamelia-provider role. No user interaction is required once that level of access is obtained.
Which deployments are affected?
Only the Premium version of the Amelia plugin is affected, because the issue requires the Employee Panel. Versions up to and including 2.4.4 are vulnerable.
What access could an attacker gain?
A wpamelia-provider can view and modify arbitrary customer records through the affected endpoint, including initiating password resets. WordPress accounts with roles up to Editor may be taken over when the account holder has made an Amelia booking.
How can I assess whether exposure exists?
Check whether the Premium Amelia plugin with the Employee Panel is installed at version 2.4.4 or earlier, and review which users hold the wpamelia-provider role. Also identify WordPress users up to Editor who have made Amelia bookings, as those accounts may be exposed to takeover.