CVE-2026-14213 - Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR
CVE ID :CVE-2026-14213
Published : Aug. 13, 2026, 6:17 a.m. | 1 hour, 11 minutes ago
Description :The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 13, 2026, 6:17 a.m. | 1 hour, 11 minutes ago
Description :The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...