5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Description
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark payments as refunded, trigger sending of queued notifications (emails/SMS/WhatsApp), and access debug information among other things.
Basic Information
ID
CVE-2025-14720
Source
Wordfence
Published
Jan 9, 2026 at 06:34
Affected Product
Vendor
ameliabooking
Product
Booking for Appointments and Events Calendar – Amelia
Version
*
Affected Versions
ameliabooking Booking for Appointments and Events Calendar – Amelia *