{"api_version":"1","generated_at":"2026-08-10T11:35:01+00:00","cve":"CVE-2026-14211","urls":{"html":"https://cve.report/CVE-2026-14211","api":"https://cve.report/api/cve/CVE-2026-14211.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-14211","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-14211"},"summary":{"title":"Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR","description":"The Booking for Appointments and Events Calendar  WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-10 07:16:46","updated_at":"2026-08-10 07:16:46"},"problem_types":["CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/511d2d53-34c5-4457-bc25-6f9105b57825/","name":"https://wpscan.com/vulnerability/511d2d53-34c5-4457-bc25-6f9105b57825/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-14211","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14211","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Booking for Appointments and Events Calendar","version":"affected 9.0 9.7 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Mustafa Ahmed","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Booking for Appointments and Events Calendar","vendor":"Unknown","versions":[{"lessThan":"9.7","status":"affected","version":"9.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Mustafa Ahmed"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Booking for Appointments and Events Calendar  WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers."}],"problemTypes":[{"descriptions":[{"description":"CWE-639 Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-10T06:00:18.388Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/511d2d53-34c5-4457-bc25-6f9105b57825/"}],"source":{"discovery":"EXTERNAL"},"title":"Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-14211","datePublished":"2026-08-10T06:00:18.388Z","dateReserved":"2026-06-30T11:10:10.750Z","dateUpdated":"2026-08-10T06:00:18.388Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 07:16:46","lastModifiedDate":"2026-08-10 07:16:46","problem_types":["CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"14211","Ordinal":"1","Title":"Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure ","CVE":"CVE-2026-14211","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"14211","Ordinal":"1","NoteData":"The Booking for Appointments and Events Calendar  WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers.","Type":"Description","Title":"Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure "}]}}}