Description
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.
Published: 2026-08-13
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from the Booking for Appointments and Events Calendar WordPress plugin. Prior to version 2.4.6, the plugin fails to confirm that an authenticated employee (provider) is actually assigned to an appointment before allowing them to view it. This flaw means that any logged‑in employee can read the personal details of any customer by supplying the appointment identifier. The impact is that confidential customer information—such as contact details, booking dates, and any personal notes—is exposed to unauthorised parties, potentially violating privacy and data protection regulations.

Affected Systems

WordPress sites running the Booking for Appointments and Events Calendar plugin with a version number earlier than 2.4.6. The vendor is unknown and the product is the plugin listed above.

Risk and Exploitability

No CVSS score has been published, and the EPSS score is currently unavailable, so precise quantification of risk is limited. The flaw requires the attacker to be an authenticated employee, which narrows the threat actor set to internal staff, but the impact is significant because it allows disclosure of personal customer data. Because the vulnerability is a classic IDOR, an attacker who discovers the pattern can easily enumerate appointment IDs and harvest data. The vulnerability is not yet listed in CISA KEV, but it should be considered a high‑risk exposure given the potential legal and reputational consequences.

Generated by OpenCVE AI on August 13, 2026 at 07:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Booking for Appointments and Events Calendar plugin to version 2.4.6 or later.
  • If an update is not immediately possible, restrict employee roles so that only providers assigned to an appointment can access that record—adjust role capabilities or add a custom capability check.
  • Conduct an audit of current appointments to ensure no sensitive data is exposed due to previous versions.
  • Monitor access logs for unusual appointment access patterns.

Generated by OpenCVE AI on August 13, 2026 at 07:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Ameliabooking
Ameliabooking booking For Appointments And Events Calendar
Wordpress
Wordpress wordpress
Vendors & Products Ameliabooking
Ameliabooking booking For Appointments And Events Calendar
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Thu, 13 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.
Title Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR
References

Subscriptions

Ameliabooking Booking For Appointments And Events Calendar
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-13T06:00:13.140Z

Reserved: 2026-06-30T11:17:06.208Z

Link: CVE-2026-14213

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T06:17:38.010

Modified: 2026-08-13T06:17:38.010

Link: CVE-2026-14213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:15:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key