Unauthorized Access Vulnerability in Booking for Appointments and Events Calendar Plugin by WordPress
CVE-2025-14720
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 January 2026
What is CVE-2025-14720?
The Amelia plugin for WordPress is susceptible to security issues that arise from the absence of necessary capability checks on AJAX actions. This flaw permits unauthenticated attackers to manipulate crucial operations, such as marking payments as refunded, dispatching queued notifications through various channels (including email, SMS, and WhatsApp), and gaining access to sensitive debug information. It is critical for users of the Amelia plugin to update to the latest version to mitigate potential risks.
Affected Version(s)
Booking for Appointments and Events Calendar β Amelia 0 <= 1.2.38