CVE-2026-16582 UNKNOWN

CVE-2026-16582

Published: 2026-09-17

Description

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This is due to the plugin accepting a client-supplied package-redemption identifier as proof of payment without validating it. This makes it possible for unauthenticated attackers to create approved appointment bookings without completing payment

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…