Booking For Appointments And Events Calendar

WordPress plugin · booking-for-appointments-and-events-calendar · WordPress.org ↗
0
Critical
1
High
9
Known total
0
Unfixed
Running Booking For Appointments And Events Calendar on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 7.2
Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover
CVE.org
>=0, <2.4.10 v2.4.10 CVE-2026-77705 Sep 12, 2026
MEDIUM
CVSS 5.3
Amelia Pro 9.0 - 9.8 - Unauthenticated Payment Bypass
CVE.org
>=9.0, <9.8.1 v9.8.1 CVE-2026-77689 Sep 12, 2026
MEDIUM
CVSS 6.5
Amelia < 2.4.9 - Unauthenticated Post-Booking Action Trigger
CVE.org
>=0, <2.4.9 v2.4.9 CVE-2026-14215 Sep 2, 2026
MEDIUM
CVSS 4.7
Amelia Pro < 9.8 - Provider+ Arbitrary Provider Password Update via IDOR
CVE.org
>=9.0, <9.8 v9.8 CVE-2026-14212 Aug 26, 2026
MEDIUM
CVSS 6.5
Amelia < 2.4.7 - Unauthenticated Notification Queue Dispatch
CVE.org
>=0, <2.4.7 v2.4.7 CVE-2026-14216 Aug 26, 2026
LOW
CVSS 2.7
Amelia 1.2.32 - 2.4.8 - Amelia Customer+ Appointment Status Update and Self-Approval
CVE.org
>=1.2.32, <2.4.9 v2.4.9 CVE-2026-77704 Aug 29, 2026
LOW
CVSS 3.7
Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR
CVE.org
>=0, <2.4.6 v2.4.6 CVE-2026-14213 Aug 13, 2026
LOW
CVSS 3.8
Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR
CVE.org
>=9.0, <9.7 v9.7 CVE-2026-14211 Aug 10, 2026
LOW
CVSS 2.7
Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment
CVE.org
>=0, <2.4.4 v2.4.4 CVE-2026-14214 Aug 1, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.