Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Threat Entry
Updated 2026-08-01
CVE-2026-14214 - Booking For Appointments And Events Calendar Plugin
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.
PLUGIN
Booking For Appointments And Events Calendar
CVE-2026-14214
Risk Score
