Description
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
Published: 2026-08-26
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Booking for Appointments and Events Calendar WordPress plugin (often referred to as Amelia) before version 2.4.7 processes any pending notification queue without checking if the caller is authenticated. This flaw permits any user that can reach the site to cause the queued notifications and any associated integration callbacks to be dispatched, potentially leading to unsolicited email spam, unwanted contact with third‑party services, or leakage of sensitive information carried by the notifications.

Affected Systems

WordPress sites that run the Amelia plugin in any version older than 2.4.7 are affected. Those sites typically host public‑facing appointment or event scheduling interfaces where the plugin’s notification system triggers email alerts or external integrations.

Risk and Exploitability

The CVSS score is missing from the provided data, but the vulnerability requires no authentication and can be triggered by a simple HTTP request from any remote host with network access to the site. EPSS is not reported and the issue is not listed in the CISA KEV catalog, indicating no current widespread exploitation yet. Nevertheless, the risk is moderate to high because the flaw enables high‑volume notification dispatch, which can be abused for spam, denial of service to participants, or unintended data exposure through callbacks.

Generated by OpenCVE AI on August 26, 2026 at 07:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Amelia plugin to version 2.4.7 or later, where the access control is fixed.
  • If an immediate update is not possible, block access to the endpoint that processes the notification queue by adding HTTP authentication or a firewall rule that limits requests to privileged users.
  • Disable automatic notification queue processing in the plugin’s settings while awaiting the patch to prevent accidental dispatch of queued messages.

Generated by OpenCVE AI on August 26, 2026 at 07:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 26 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
Title Amelia < 2.4.7 - Unauthenticated Notification Queue Dispatch
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-26T14:43:10.496Z

Reserved: 2026-06-30T11:19:43.864Z

Link: CVE-2026-14216

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T07:30:16Z

Weaknesses