What is CVE-2026-14239?
CVE-2026-14239 is a Stored Cross-Site Scripting (XSS) vulnerability in the Tourmaster WordPress plugin before version 5.4.8. Due to missing nonce checks and lack of escaping on a custom-filter label, an unauthenticated attacker can trick a logged-in administrator into storing malicious scripts when saving filter parameters. Updating the plugin to version 5.4.8 or later is recommended.
Azərbaycanca: CVE-2026-14239 Tourmaster WordPress plugin-inin 5.4.8-dən əvvəlki versiyalarında aşkarlanmış “Stored Cross-Site Scripting” (XSS) zəifliyidir. “custom-filter label” parametrini saxlayarkən “nonce” yoxlamasının aparılmaması və çıxışın ekranlaşdırılmaması səbəbindən, autentifikasiya olunmamış hücumçu daxil olmuş administratoru aldadaraq zərərli skript yerləşdirə bilər. Plugin-i 5.4.8 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What causes the Stored XSS vulnerability in Tourmaster plugin CVE-2026-14239?
The vulnerability is caused by missing nonce checks and lack of escaping on the 'custom-filter label' parameter when saving, allowing an unauthenticated attacker to trick a logged-in administrator into storing malicious scripts.
To which version should the Tourmaster plugin be updated to mitigate CVE-2026-14239?
Updating the Tourmaster plugin to version 5.4.8 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.