🔐 CVE Alert

CVE-2026-14216

MEDIUM 5.3

Amelia < 2.4.7 - Unauthenticated Notification Queue Dispatch

CVSS Score
5.3
EPSS Score
0.2%
EPSS Percentile
13th

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.

Vendor unknown
Product booking for appointments and events calendar
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown booking for appointments and events calendar

Be the first to know when new medium vulnerabilities affecting unknown booking for appointments and events calendar are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Booking for Appointments and Events Calendar
0 < 2.4.7

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/c38bf5b3-902c-4126-a9a3-42d9f2d359c3/

Credits

Manuel Martínez Casasola WPScan