PT-2026-66385 · Undefined · Undefined
CVE-2026-14239
·
Published
2026-07-30
·
Updated
2026-08-04
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
tourmaster WordPress plugin versions prior to 5.4.8
Description
The plugin fails to perform a nonce check when storing a custom-filter label received from a request parameter and does not escape this label when displaying it on the filter admin page. This allows an unauthenticated attacker to use Cross-Site Request Forgery (CSRF) to trick a logged-in administrator into storing malicious JavaScript, which then executes within the administrative area. This is a stored Cross-Site Scripting (XSS) issue, where XSS is a technique that allows an attacker to execute scripts in the victim's browser, and CSRF is a method that forces a user to execute unwanted actions on a web application in which they are currently authenticated.
Recommendations
Update tourmaster WordPress plugin to version 5.4.8 or later.
Exploit
Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined