Beveiligingsadvies

CVE-2026-14214

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-01 06:00:13
Laatst bijgewerkt 2026-08-05 16:18:39
Toegewezen door WPScan
CVSS-score 2.7
Status PUBLISHED

Beschrijving

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.