CVE-2026-14240 UNKNOWN

CVE-2026-14240

Published: 2026-08-06

Description

The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated users to download the exported customers' personal information once an administrator has run an export.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…