The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
We have discovered 1,053 live websites that are affected by CVE-2026-14216.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,053 live websites (99% of Ameliabooking install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 48 versions ( 94% of all versions) |
| 245 websites | |
| 109 websites | |
| 90 websites | |
| 64 websites | |
| 63 websites | |
| 37 websites | |
| 31 websites | |
| 29 websites | |
| 28 websites | |
| 27 websites |
| .com | 444 websites |
| .de | 58 websites |
| .it | 45 websites |
| .org | 41 websites |
| .co.uk | 38 websites |
| .fr | 36 websites |
| .nl | 33 websites |
| .pl | 21 websites |
| .ch | 18 websites |
| .com.au | 18 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *************.net | ***,*** | ||
| *******.com | ***,*** | ||
| ********************.com | ***,*** | ||
| ***.***.na | ***,*** | ||
| *******.nl | ***,*** | ||
| *********.edu | ***,*** | ||
| *********.nl | ***,*** | ||
| *****************.dk | ***,*** | ||
| ***********.**.za | *,***,*** | ||
| ******.com | *,***,*** |
FAQ