PoC Index82,564 CVEs with PoCs

CVE-2026-14215

Amelia < 2.4.9 - Unauthenticated Post-Booking Action Trigger

MEDIUM 6.5EPSS 0.3%

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier.

Affected
Booking for Appointments and Events Calendar
CVSS v3.1 CNA
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
EPSS
0.30% chance of exploitation in the next 30 days, 23rd percentile
Published
2026-09-02

Proof-of-concept exploits (1)

References