Unauthorized Access Vulnerability in Booking for Appointments and Events Calendar Plugin by WordPress
CVE-2025-14720

5.3MEDIUM

What is CVE-2025-14720?

The Amelia plugin for WordPress is susceptible to security issues that arise from the absence of necessary capability checks on AJAX actions. This flaw permits unauthenticated attackers to manipulate crucial operations, such as marking payments as refunded, dispatching queued notifications through various channels (including email, SMS, and WhatsApp), and gaining access to sensitive debug information. It is critical for users of the Amelia plugin to update to the latest version to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Booking for Appointments and Events Calendar – Amelia * <= 1.2.38

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

M Indra Purnama
.