
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14720 is a Missing Authorization vulnerability in the Booking for Appointments and Events Calendar – Amelia plugin for WordPress. It affects all versions up to and including 1.2.38, allowing unauthenticated attackers to perform unauthorized actions via multiple unprotected AJAX endpoints. The vulnerability was published on January 9, 2026, and was reported by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, NVD).
The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to perform capability checks on multiple WordPress AJAX action handlers, meaning any unauthenticated HTTP request can invoke privileged functionality. Specifically, the SquareRefundWebhookCommandHandler and related AJAX handlers do not verify that the caller has appropriate WordPress user capabilities before executing sensitive operations. An attacker can craft direct HTTP POST requests to WordPress's admin-ajax.php endpoint targeting these unprotected actions without any authentication or session token (Wordfence, WordPress Trac).
Successful exploitation allows unauthenticated remote attackers to mark payments as refunded (manipulating financial records), trigger the sending of queued notifications via email, SMS, or WhatsApp (potentially causing spam or social engineering abuse), and access plugin debug information that may expose sensitive configuration or operational data. While confidentiality and availability impacts are rated as none, the integrity impact enables financial record manipulation that could disrupt business operations for sites using Amelia for appointment and event booking (Wordfence, NVD).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14720. The EPSS score is approximately 0.06%, indicating a low probability of exploitation in the near term. The vulnerability requires no authentication, no user interaction, and no special privileges, making it trivially exploitable by any network-accessible attacker against a vulnerable installation. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of this report (Wordfence, NVD).
/wp-content/plugins/ameliabooking/ for publicly accessible plugin files.https://target-site.com/wp-admin/admin-ajax.php with the appropriate action parameter corresponding to a vulnerable handler (e.g., the Square refund webhook handler or notification trigger)./wp-admin/admin-ajax.php with Amelia-specific action parameter values (e.g., related to refunds, notifications, or debug actions) from unexpected IP addresses.POST /wp-admin/admin-ajax.php requests without a valid session cookie or nonce, particularly targeting Amelia plugin action names.Update the Amelia plugin to version 1.2.39 or later, which introduces proper capability checks on the affected AJAX action handlers (WordPress Trac). As a temporary workaround, site administrators can use a Web Application Firewall (WAF) — such as Wordfence — to block unauthenticated POST requests to admin-ajax.php targeting Amelia-specific action names. Disabling the plugin entirely until patching is feasible is also an option for sites where booking functionality is not immediately critical (Wordfence).
Wordfence, which discovered and reported the vulnerability, published a threat intelligence entry detailing the affected versions and impact. No significant broader media coverage or notable researcher commentary beyond the initial Wordfence disclosure has been identified for this medium-severity vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."