๐Ÿ” CVE Alert

CVE-2026-14212

MEDIUM 4.7

Amelia Pro < 9.8 - Provider+ Arbitrary Provider Password Update via IDOR

CVSS Score
4.7
EPSS Score
0.2%
EPSS Percentile
7th

The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password and take over their account.

Vendor unknown
Product booking for appointments and events calendar
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown booking for appointments and events calendar

Be the first to know when new medium vulnerabilities affecting unknown booking for appointments and events calendar are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Booking for Appointments and Events Calendar
9.0 < 9.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/5afb51cc-8e1e-4c3c-aba6-6789e89161ae/

Credits

Haitam Lazaar WPScan