What is CVE-2026-14240?
In the Tourmaster WordPress plugin before version 5.4.9, the order/booking export is written to a fixed, predictable file in a publicly accessible directory without any access control, allowing unauthenticated users to download customers' personal data once an admin runs an export. Immediate update to the latest patched version is strongly recommended.
Azərbaycanca: Tourmaster WordPress plugin-inin 5.4.9-dan əvvəlki versiyalarında sifariş/rezervasiya ixracı ictimaiyyətə açıq qovluqda sabit adlı fayla yazılır və giriş nəzarəti yoxdur. Bu boşluq autentifikasiya olunmamış istifadəçilərə administrator ixrac əməliyyatını icra etdikdən sonra müştərilərin şəxsi məlumatlarını yükləməyə imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What does the CVE-2026-14240 vulnerability in the Tourmaster plugin allow?
It allows unauthenticated users to download customers' personal data once an admin runs an export.
Which versions of Tourmaster are affected by CVE-2026-14240 and how to mitigate?
Versions before 5.4.9 are affected. Immediate update to the latest patched version is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.