Unauthorized Access Vulnerability in Booking for Appointments and Events Calendar Plugin by WordPress
CVE-2025-14720
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 January 2026
What is CVE-2025-14720?
The Amelia plugin for WordPress is susceptible to security issues that arise from the absence of necessary capability checks on AJAX actions. This flaw permits unauthenticated attackers to manipulate crucial operations, such as marking payments as refunded, dispatching queued notifications through various channels (including email, SMS, and WhatsApp), and gaining access to sensitive debug information. It is critical for users of the Amelia plugin to update to the latest version to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Booking for Appointments and Events Calendar β Amelia * <= 1.2.38
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved