Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoodLayers Tourmaster tourmaster allows Reflected XSS.This issue affects Tourmaster: from n/a through < 5.4.1.
Published: 2025-04-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GoodLayers Tourmaster plugins older than version 5.4.1 contain an improper neutralization of user supplied data when generating web pages, resulting in a reflected cross‑site scripting vulnerability. An attacker that can provoke the plugin to return a page containing crafted input can inject arbitrary JavaScript that is executed in the browser of visitors who view the affected page. This can lead to session hijacking, credential theft, defacement, or further propagation of malware on victim sites.

Affected Systems

WordPress installations that have the GoodLayers Tourmaster plugin at a version earlier than 5.4.1 are affected. The vulnerability applies to all releases of Tourmaster from its initial release up to the pre‑5.4.1 series.

Risk and Exploitability

The CVSS score of 7.1 classifies this as a medium‑to‑high severity issue. The EPSS score of less than 1% indicates that exploitation is currently considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to craft a link or form that causes a vulnerable Tourmaster page to reflect the payload, implying a web‑based, remote exploitation path that requires user interaction.

Generated by OpenCVE AI on May 1, 2026 at 10:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GoodLayers Tourmaster plugin to version 5.4.1 or newer to remediate the reflected XSS flaw.
  • If an upgrade is not feasible, disable or delete the Tourmaster plugin to eliminate the vulnerable code path.
  • Deploy a web application firewall or security plugin that filters and sanitizes user input, blocking reflected XSS vectors.

Generated by OpenCVE AI on May 1, 2026 at 10:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11101 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Tourmaster allows Reflected XSS. This issue affects Tourmaster: from n/a through n/a.
History

Thu, 30 Apr 2026 03:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Tourmaster allows Reflected XSS. This issue affects Tourmaster: from n/a through n/a. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoodLayers Tourmaster tourmaster allows Reflected XSS.This issue affects Tourmaster: from n/a through < 5.4.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 15 Apr 2025 22:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Tourmaster allows Reflected XSS. This issue affects Tourmaster: from n/a through n/a.
Title WordPress Tourmaster plugin < 5.4.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:29.244Z

Reserved: 2025-04-14T11:30:45.183Z

Link: CVE-2025-32923

cve-icon Vulnrichment

Updated: 2025-04-16T14:11:40.820Z

cve-icon NVD

Status : Deferred

Published: 2025-04-15T22:15:28.290

Modified: 2026-04-23T15:29:22.410

Link: CVE-2025-32923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T10:15:17Z

Weaknesses