Junglewise Threat Intelligence

CVE-2026-14311: WordPress Amelia plugin missing ownership verification in customer endpoint

CVE-2026-14311 · Severity: medium · CVSS 5.4 · Published 2026-09-17

Technologies: Booking for Appointments and Events Calendar Amelia.

Executive brief

Amelia is a popular WordPress plugin for managing appointments and event bookings. The plugin's Premium version contains a flaw that allows certain site administrators (those with the wpamelia-provider role) to view and modify customer data belonging to other users without proper authorization, including resetting customer passwords and potentially taking over WordPress accounts of users who have made bookings through the plugin.

Technical details

The vulnerability is a missing ownership verification flaw in the /users/customers/<id> REST API endpoint. Authenticated users with the wpamelia-provider role can send requests to access or modify arbitrary customer records without the application checking whether the requesting user owns or has permission to access that customer. An attacker with this role can view sensitive customer information, reset passwords, and potentially take over WordPress accounts with Editor role or lower if that user made an Amelia booking. The vulnerability affects all Premium versions up to and including 2.4.4; the free version is not impacted. No user interaction is required—only network access and valid plugin credentials.

Affected products

  • Booking for Appointments and Events Calendar Amelia up to and including 2.4.4

Timeline

  • 2026-09-17: disclosed

References