Impact
The Tourmaster WordPress plugin, when running an order or booking export, writes the resulting file to a fixed location inside a publicly accessible directory without any access control. After an administrator has performed an export, any unauthenticated user can retrieve the file and obtain customers' personal information, exposing sensitive data. This vulnerability is a direct information disclosure arising from a lack of proper access checks on exported exports.
Affected Systems
This flaw affects installations of the Tourmaster plugin for WordPress with versions prior to 5.4.9. The vendor is not listed, but the product name and version range are known from the advisories. No other products are cited as affected.
Risk and Exploitability
The attack path is simple: an attacker first triggers an export by an administrator, then accesses the predictable URL to download the file. The EPSS score is not provided, and the vulnerability is not listed in KEV, however the lack of authentication requirements means any user on the site can download the file. The consequence is exposure of personally identifiable customer data, posing a moderate to high privacy risk for users of the affected plugin.
OpenCVE Enrichment