Feed/CVE-2026-14214
CVE-2026-14214LOWCVSS 2.7

CVE-2026-14214

Published Aug 1, 2026·Updated Aug 5, 2026

NVD Description

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free