CVE-2026-14240

The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated users to download the exported customers' personal information once an administrator has run an export.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-06 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-14240

Mitre link : CVE-2026-14240

CVE.ORG link : CVE-2026-14240


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor