PatchSiren

tourmaster CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM tourmaster CVE published 2026-08-06

CVE-2026-14240

The tourmaster WordPress plugin before 5.4.9 has a vulnerability that allows unauthenticated users to download exported customers' personal information. This is because the plugin writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control. Administrators of WordPress sites using the tourmaster plugin, especially those handling customer data [truncated]