CVE-2026-14311: Booking for Appointments and Events Calendar – Amelia (Premium) <= 2.4.4 - Authenticated (Custom+) Missing Authorization to Limited Account Takeover

Published Sep 17, 2026
·
Updated

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with wpamelia-provider role, to view and modify arbitrary customers, including password reset. Takeover of WordPress user accounts, with the roles up to Editor, is also possible if that user had made an Amelia booking. This vulnerability affects only the Premium version of the plugin, where the Employee Panel is present.

Affected Software

1 affected component
WordPress plugin: Booking for Appointments and Events Calendar – Amelia (Premium)<=2.4.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Booking for Appointments and Events Calendar – Amelia (Premium) to a version that resolves this vulnerability.

    Fixed in 2.4.4
  2. Compensating control

    Because the issue allows authenticated attackers (wpamelia-provider role) to view/modify arbitrary customers (including password reset) when Employee Panel is present in the Amelia Premium plugin, restrict the wpamelia-provider role access so only trusted accounts can use it until the plugin is updated.

Event History

Sep 17, 2026
CVE Published
via MITRE·09:28 PM
Data Sourced
via MITRE·09:28 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must already be authenticated to WordPress with the wpamelia-provider role. No user interaction is required once that level of access is obtained.

2

Which deployments are affected?

Only the Premium version of the Amelia plugin is affected, because the issue requires the Employee Panel. Versions up to and including 2.4.4 are vulnerable.

3

What access could an attacker gain?

A wpamelia-provider can view and modify arbitrary customer records through the affected endpoint, including initiating password resets. WordPress accounts with roles up to Editor may be taken over when the account holder has made an Amelia booking.

4

How can I assess whether exposure exists?

Check whether the Premium Amelia plugin with the Employee Panel is installed at version 2.4.4 or earlier, and review which users hold the wpamelia-provider role. Also identify WordPress users up to Editor who have made Amelia bookings, as those accounts may be exposed to takeover.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203