What is CVE-2026-14214?
This vulnerability exists in the 'Booking for Appointments and Events Calendar' (Amelia) WordPress plugin before version 2.4.4. It allows a user with the 'Amelia Manager' role to modify arbitrary columns of any user record via the customer import feature. Updating the plugin to version 2.4.4 or later is required.
Azərbaycanca: Bu boşluq 'Booking for Appointments and Events Calendar' (Amelia) WordPress plaginindəki səhv konfiqurasiyadır. 2.4.4 versiyasından əvvəl müştəri idxal funksiyası 'Amelia Manager' roluna malik istifadəçiyə istənilən istifadəçi qeydinin sütunlarını dəyişməyə icazə verir. Plagin ən azı 2.4.4 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the 'Amelia' plugin are affected by CVE-2026-14214?
This vulnerability affects all versions of the 'Booking for Appointments and Events Calendar' (Amelia) WordPress plugin before version 2.4.4.
How can the vulnerability be exploited with the 'Amelia Manager' role?
The CVE-2026-14214 vulnerability allows a user with the 'Amelia Manager' role to modify arbitrary columns of any user record via the customer import feature, due to a misconfiguration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.