Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 09 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ameliabooking
Ameliabooking booking For Appointments And Events Calendar Wordpress Wordpress wordpress |
|
| Vendors & Products |
Ameliabooking
Ameliabooking booking For Appointments And Events Calendar Wordpress Wordpress wordpress |
Fri, 09 Jan 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark payments as refunded, trigger sending of queued notifications (emails/SMS/WhatsApp), and access debug information among other things. | |
| Title | Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-01-09T19:10:22.011Z
Reserved: 2025-12-15T14:10:14.139Z
Link: CVE-2025-14720
Updated: 2026-01-09T19:10:19.414Z
Status : Received
Published: 2026-01-09T07:16:01.153
Modified: 2026-01-09T07:16:01.153
Link: CVE-2025-14720
No data.
OpenCVE Enrichment
Updated: 2026-01-09T13:23:46Z