Ultimate Guide: CVE-2025-14720 - Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - missing author...

Ultimate Guide: CVE-2025-14720 - Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - missing author...

CVE ID : CVE-2025-14720 Published : Jan. 9, 2026, 6:34 a.m. | 32 minutes ago Description : The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark payments as refunded, trigger sending of queued notifications (emails/SMS/WhatsApp), and access debug information among other things. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
Jan. 9, 2026
Affected Product: WordPress

Source: Telegram CVE Monitor