CVE-2025-14720: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14720 is a Missing Authorization vulnerability in the Booking for Appointments and Events Calendar – Amelia plugin for WordPress. It affects all versions up to and including 1.2.38, allowing unauthenticated attackers to perform unauthorized actions via multiple unprotected AJAX endpoints. The vulnerability was published on January 9, 2026, and was reported by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, NVD).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to perform capability checks on multiple WordPress AJAX action handlers, meaning any unauthenticated HTTP request can invoke privileged functionality. Specifically, the SquareRefundWebhookCommandHandler and related AJAX handlers do not verify that the caller has appropriate WordPress user capabilities before executing sensitive operations. An attacker can craft direct HTTP POST requests to WordPress's admin-ajax.php endpoint targeting these unprotected actions without any authentication or session token (Wordfence, WordPress Trac).

Impact

Successful exploitation allows unauthenticated remote attackers to mark payments as refunded (manipulating financial records), trigger the sending of queued notifications via email, SMS, or WhatsApp (potentially causing spam or social engineering abuse), and access plugin debug information that may expose sensitive configuration or operational data. While confidentiality and availability impacts are rated as none, the integrity impact enables financial record manipulation that could disrupt business operations for sites using Amelia for appointment and event booking (Wordfence, NVD).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14720. The EPSS score is approximately 0.06%, indicating a low probability of exploitation in the near term. The vulnerability requires no authentication, no user interaction, and no special privileges, making it trivially exploitable by any network-accessible attacker against a vulnerable installation. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of this report (Wordfence, NVD).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Amelia booking plugin (versions ≤ 1.2.38) using tools like WPScan, Shodan, or by checking /wp-content/plugins/ameliabooking/ for publicly accessible plugin files.
  2. Identify vulnerable AJAX actions: Review the Amelia plugin's registered AJAX hooks (e.g., via source code or the WordPress Trac changeset) to enumerate unprotected action names handled without capability checks.
  3. Craft unauthenticated AJAX request: Send an HTTP POST request to https://target-site.com/wp-admin/admin-ajax.php with the appropriate action parameter corresponding to a vulnerable handler (e.g., the Square refund webhook handler or notification trigger).
  4. Manipulate payment records: Include parameters to mark a specific payment as refunded, altering the booking system's financial records without any legitimate authorization.
  5. Trigger notifications or access debug data: Use other unprotected AJAX actions to send queued email/SMS/WhatsApp notifications to arbitrary recipients, or retrieve debug information that may expose internal configuration details (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unusual unauthenticated POST requests to /wp-admin/admin-ajax.php with Amelia-specific action parameter values (e.g., related to refunds, notifications, or debug actions) from unexpected IP addresses.
  • Logs: WordPress access logs showing repeated POST /wp-admin/admin-ajax.php requests without a valid session cookie or nonce, particularly targeting Amelia plugin action names.
  • Application: Unexpected payment status changes (e.g., payments marked as refunded) in the Amelia booking dashboard without corresponding legitimate user activity.
  • Notifications: Unexpected bulk sending of email, SMS, or WhatsApp notifications from the booking system not initiated by site administrators.

Mitigation and workarounds

Update the Amelia plugin to version 1.2.39 or later, which introduces proper capability checks on the affected AJAX action handlers (WordPress Trac). As a temporary workaround, site administrators can use a Web Application Firewall (WAF) — such as Wordfence — to block unauthenticated POST requests to admin-ajax.php targeting Amelia-specific action names. Disabling the plugin entirely until patching is feasible is also an option for sites where booking functionality is not immediately critical (Wordfence).

Community reactions

Wordfence, which discovered and reported the vulnerability, published a threat intelligence entry detailing the affected versions and impact. No significant broader media coverage or notable researcher commentary beyond the initial Wordfence disclosure has been identified for this medium-severity vulnerability.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management