Junglewise Threat Intelligence

CVE-2026-14216: Amelia Booking unauthenticated notification dispatch

CVE-2026-14216 · Severity: medium · CVSS 6.5 · Published 2026-08-26

Vendors: Elated-Themes.

Executive brief

Amelia is a popular WordPress plugin for managing appointments and events bookings. The plugin before version 2.4.7 allows attackers to send queued email notifications and trigger post-booking actions without authentication. An attacker could spam customers and providers with unwanted notifications or execute automated workflows, disrupting business operations and damaging customer trust.

Technical details

The vulnerability is an authentication bypass (CWE-287) in the Amelia WordPress plugin's notification queue processing endpoint. The `/notifications/undelivered/send` AJAX action does not validate user authentication or capability checks before processing pending notifications and integration callbacks. An unauthenticated attacker can directly call `wp-admin/admin-ajax.php?action=wpamelia_api&call=/notifications/undelivered/send` to dispatch all queued email, SMS, and WhatsApp notifications and trigger post-booking automation chains. The attack requires no user interaction or valid credentials. A patch is available in version 2.4.7 and later.

Affected products

  • Elated Themes Amelia before 2.4.7

Timeline

  • 2026-08-24: disclosed
  • 2026-08-26: patched: Version 2.4.7 and later
  • 2026-08-26: advisory

References