CVE-2026-14240
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
06/08/2026
Last modified:
06/08/2026
Description
The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated users to download the exported customers' personal information once an administrator has run an export.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM



