Impact
The GoodLayers Tourmaster WordPress plugin contains a subscriber‑level Local File Inclusion flaw that lets an attacker supply crafted input to cause the server to read arbitrary files residing on the web host. If exploited, the plugin can return the contents of files such as wp‑config.php, database dumps, or sensitive configuration files, exposing confidential data. The weakness is classified as CWE‑98.
Affected Systems
Any WordPress installation that has the Tourmaster plugin version 5.4.5 or earlier and still uses that version is vulnerable. Sites running newer releases or those that have removed the plugin are not affected.
Risk and Exploitability
The high CVSS score of 7.5 indicates serious potential impact; the EPSS score of <1% shows that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be web‑based, where a subscriber‑level user can construct a request to the plugin’s file‑handling endpoint and supply a path that the plugin will read and return.
OpenCVE Enrichment