Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-14214

Опубликовано: 01 авг. 2026
Источник: nvd
CVSS3: 2.7
EPSS Низкий

Описание

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.

EPSS

Процентиль: 6%
0.00163
Низкий

2.7 Low

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 2.7
github
около 2 месяцев назад

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.

EPSS

Процентиль: 6%
0.00163
Низкий

2.7 Low

CVSS3

Дефекты

CWE-287