VYPR

Booking for Appointments and Events Calendar

by WordPress

CVEs (2)

  • CVE-2026-14214LowAug 1, 2026
    risk 0.18cvss 2.7epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the…

  • CVE-2026-14211Aug 10, 2026
    risk 0.00cvss epss

    The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored…