MEDIUM
tourmaster
CVE published 2026-08-06
CVE-2026-14240
The tourmaster WordPress plugin before 5.4.9 has a vulnerability that allows unauthenticated users to download exported customers' personal information. This is because the plugin writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control. Administrators of WordPress sites using the tourmaster plugin, especially those handling customer data [truncated]