Loading market data...
← Back to CVE feed

CVE-2026-14240

MEDIUM CVSS 5.3 View on NVD ↗

Description

The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated users to download the exported customers' personal information once an administrator has run an export.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Published: Aug 06, 2026 07:16 UTC Modified: Aug 06, 2026 15:16 UTC