CVE-2026-14240: CWE-200 Information Exposure in tourmaster
CVE-2026-14240 is a medium severity information exposure vulnerability in the tourmaster WordPress plugin before version 5.4.9. The plugin writes order and booking export files to a fixed, predictable location within a publicly accessible directory without access controls. This allows unauthenticated users to download exported customer personal information after an administrator performs an export.
AI Analysis
Technical Summary
The tourmaster WordPress plugin versions prior to 5.4.9 contain an information exposure vulnerability (CWE-200) where exported order and booking data are saved to a fixed, predictable file path in a publicly accessible directory. Because there is no access control on this file, unauthenticated attackers can download sensitive customer personal information once an administrator has generated the export file. This vulnerability does not require user interaction or privileges to exploit, but depends on an administrator having performed an export.
Potential Impact
The vulnerability allows unauthenticated attackers to access and download personal customer information exported by the plugin. This exposure can lead to privacy violations and potential misuse of sensitive data. There is no indication of impact to integrity or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should avoid exporting order or booking data or restrict access to the export directory via web server configuration to prevent unauthorized downloads.
CVE-2026-14240: CWE-200 Information Exposure in tourmaster
Description
CVE-2026-14240 is a medium severity information exposure vulnerability in the tourmaster WordPress plugin before version 5.4.9. The plugin writes order and booking export files to a fixed, predictable location within a publicly accessible directory without access controls. This allows unauthenticated users to download exported customer personal information after an administrator performs an export.
CVSS v3.1
Score 5.3medium
Affected software
tourmaster
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The tourmaster WordPress plugin versions prior to 5.4.9 contain an information exposure vulnerability (CWE-200) where exported order and booking data are saved to a fixed, predictable file path in a publicly accessible directory. Because there is no access control on this file, unauthenticated attackers can download sensitive customer personal information once an administrator has generated the export file. This vulnerability does not require user interaction or privileges to exploit, but depends on an administrator having performed an export.
Potential Impact
The vulnerability allows unauthenticated attackers to access and download personal customer information exported by the plugin. This exposure can lead to privacy violations and potential misuse of sensitive data. There is no indication of impact to integrity or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should avoid exporting order or booking data or restrict access to the export directory via web server configuration to prevent unauthorized downloads.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-06-30T13:14:08.487Z
- State
- PUBLISHED
Threat ID: 6a742932bf8831d53945d6b4
Added to database: 08/06/2026, 06:26:58 UTC
Last enriched: 08/13/2026, 17:26:58 UTC
Last updated: 09/21/2026, 22:01:32 UTC
Views: 30
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.