Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-14311— Booking for Appointments and Events Calendar – Amelia (Premium) <= 2.4.4 - Authenticated (Custom+) Missing Authorization to Limited Account Takeover

Quick assessment

Affected
melograno Booking for Appointments and Events Calendar – Amelia
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述的中文翻译: WordPress 的“预约与活动日历 – Amelia”插件存在由于 接口缺失所有权验证,导致未经授权的访问和数据修改漏洞。该漏洞影响所有版本,最高至 2.4.4。 这使得拥有 角色的已认证攻击者能够查看并修改任意客户信息,包括执行密码重置。如果目标 WordPress 用户曾通过 Amelia 进行过预约,攻击者还可能接管其账户(受影响的角色最高为 Editor 角色)。 注意:此漏洞仅影响插件的高级版(Premium 版),且前提是其中存在“员工面板(Employee Panel

CVSS 5.4 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-14311

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Booking for Appointments and Events Calendar – Amelia (Premium) <= 2.4.4 - Authenticated (Custom+) Missing Authorization to Limited Account Takeover
Source: CVE Program / CVE List V5
Vulnerability Description
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with wpamelia-provider role, to view and modify arbitrary customers, including password reset. Takeover of WordPress user accounts, with the roles up to Editor, is also possible if that user had made an Amelia booking. This vulnerability affects only the Premium version of the plugin, where the Employee Panel is present.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
melograno Booking for Appointments and Events Calendar – Amelia 0 ~ 2.4.4 -

II. Public POCs for CVE-2026-14311

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14311

登录查看更多情报信息。

Patches & Fixes for CVE-2026-14311 (1)

Vendor Advisories for CVE-2026-14311 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-14311

No comments yet


Leave a comment