MEDIUM 5.3 NVD
CVE-2026-16582
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and inc
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This is due to the plugin accepting a client-supplied package-redemption identifier as proof of payment without validating it. This makes it possible for unauthenticated attackers to create approved appointment bookings without completing payment
References
- https://plugins.trac.wordpress.org/changeset/3640186
- https://www.wordfence.com/threat-intel/vulnerabilities/id/9e0c6f83-f4ca-4891-b2db-e2ac49d9
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-17 via NVD.
vulnfeed aggregates 13500 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.