CVE-2026-14214

CVE-2026-14214CVE-2026-14214

Description

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.

Scoring

Last modified2026-08-01
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.