Unauthorized Data Modification in Booking for Appointments and Events Calendar – Amelia Plugin by WordPress
CVE-2026-16582
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 September 2026
What is CVE-2026-16582?
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress contains a vulnerability that allows for unauthorized modification of data. This issue arises from the plugin's failure to validate a client-supplied package-redemption identifier as proof of payment. As a result, unauthenticated attackers are able to create appointment bookings without submitting payment, posing significant risks to system integrity and trustworthiness.
Affected Version(s)
Booking for Appointments and Events Calendar – Amelia 0 <= 2.4.5