PT-2026-66385 · Undefined · Undefined

CVE-2026-14239

·

Published

2026-07-30

·

Updated

2026-08-04

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions tourmaster WordPress plugin versions prior to 5.4.8
Description The plugin fails to perform a nonce check when storing a custom-filter label received from a request parameter and does not escape this label when displaying it on the filter admin page. This allows an unauthenticated attacker to use Cross-Site Request Forgery (CSRF) to trick a logged-in administrator into storing malicious JavaScript, which then executes within the administrative area. This is a stored Cross-Site Scripting (XSS) issue, where XSS is a technique that allows an attacker to execute scripts in the victim's browser, and CSRF is a method that forces a user to execute unwanted actions on a web application in which they are currently authenticated.
Recommendations Update tourmaster WordPress plugin to version 5.4.8 or later.

Exploit

Fix

XSS

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14239

Affected Products

Undefined