Tour Master - Tour Booking, Travel, Hotel < 5.4.8 - Unauthenticated Stored Cross-Site Scripting
high
The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a u...
- CVSS:
- 7.2
- Affected:
- up to 5.4.8
- Fixed in:
- 5.4.8
- Disclosed:
- Aug 13, 2026
CVE-2026-14239 on NVD →
Tourmaster <= 5.4.8 - Unauthenticated Information Exposure
medium
The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.8. This makes it possible for unauthenticated attackers to extract order data.
- CVSS:
- 5.3
- Affected:
- up to 5.4.8
- Fixed in:
- 5.4.9
- Disclosed:
- Jul 30, 2026
CVE-2026-14240 on NVD →
Tour Master - Tour Booking, Travel, Hotel <= 5.4.5 - Authenticated (Subscriber+) Local File Inclusion
high
The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.4.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of an...
- CVSS:
- 7.5
- Affected:
- up to 5.4.5
- Fix:
- No patched version reported
- Disclosed:
- Jun 29, 2026
CVE-2025-69133 on NVD →
Tour Master [tourmaster] < 5.3.9
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GoodLayers Tourmaster allows PHP Local File Inclusion. This issue affects Tourmaster: from n/a through 5.3.8.
- Affected:
- up to 5.3.9
- Fixed in:
- 5.3.9
- Disclosed:
- May 23, 2025
CVE-2025-48292 on NVD →
Tourmaster <= 5.3.8 - Unauthenticated Local File Inclusion
critical
The Tourmaster plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.3.8. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls,...
- CVSS:
- 9.8
- Affected:
- up to 5.3.8
- Fixed in:
- 5.3.9
- Disclosed:
- May 21, 2025
CVE-2025-48292 on NVD →
Tourmaster < 5.4.1 - Reflected Cross-Site Scripting
medium
The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 5.4.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...
- CVSS:
- 6.1
- Affected:
- up to 5.4.1
- Fixed in:
- 5.4.1
- Disclosed:
- Apr 15, 2025
CVE-2025-32923 on NVD →
Tour Master [tourmaster] < 5.4.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Tourmaster allows Reflected XSS. This issue affects Tourmaster: from n/a through n/a.
- Affected:
- up to 5.4.1
- Fixed in:
- 5.4.1
- Disclosed:
- Apr 15, 2025
CVE-2025-32923 on NVD →
Tour Master [tourmaster] < 5.3.8
unknown
[en] The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up to, and including, 5.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This make...
- Affected:
- up to 5.3.8
- Fixed in:
- 5.3.8
- Disclosed:
- Feb 18, 2025
CVE-2024-13369 on NVD →
Tour Master - Tour Booking, Travel, Hotel <= 5.3.7 - Authenticated (Subscriber+) SQL Injection via review_id Parameter
medium
The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up to, and including, 5.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...
- CVSS:
- 6.5
- Affected:
- up to 5.3.7
- Fixed in:
- 5.3.8
- Disclosed:
- Feb 17, 2025
CVE-2024-13369 on NVD →
Tour Master [tourmaster] < 5.3.5
unknown
[en] The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
- Affected:
- up to 5.3.5
- Fixed in:
- 5.3.5
- Disclosed:
- Jan 30, 2025
CVE-2024-12400 on NVD →
Tour Master - Tour Booking, Travel, Hotel <= 5.3.4 - Reflected Cross-Site Scripting
medium
The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.3.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 5.3.4
- Fixed in:
- 5.3.5
- Disclosed:
- Jan 9, 2025
CVE-2024-12400 on NVD →
Tour Master [tourmaster] < 5.3.4
unknown
[en] The tourmaster WordPress plugin before 5.3.4 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.
- Affected:
- up to 5.3.4
- Fixed in:
- 5.3.4
- Disclosed:
- Jan 6, 2025
CVE-2024-11356 on NVD →
Tour Master - Tour Booking, Travel, Hotel < 5.3.4 - Unauthenticated Stored Cross-Site Scripting via Room Booking
high
The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via room booking in all versions up to 5.3.4 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- CVSS:
- 7.2
- Affected:
- up to 5.3.4
- Fixed in:
- 5.3.4
- Disclosed:
- Dec 16, 2024
CVE-2024-11356 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database