Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 05 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-749 |
Wed, 05 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
cvssV3_1
|
Sun, 02 Aug 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-749 |
Sat, 01 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request. | |
| Title | Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-05T16:18:39.678Z
Reserved: 2026-06-30T11:19:35.181Z
Link: CVE-2026-14214
Updated: 2026-08-05T15:58:12.770Z
Status : Received
Published: 2026-08-01T07:16:29.990
Modified: 2026-08-05T17:16:40.813
Link: CVE-2026-14214
No data.
OpenCVE Enrichment
Updated: 2026-08-05T20:45:05Z