Impact
The Tourmaster plugin for WordPress, in versions 5.4.9 and earlier, contains an unauthenticated XSS flaw that permits an attacker to inject malicious scripts through unfiltered input. The vulnerability does not provide direct code execution on the server, but can alter page content, steal session cookies, or hijack user accounts, thereby compromising the integrity and confidentiality of user sessions and defacing site content.
Affected Systems
Sites running the GoodLayers Tourmaster plugin version 5.4.9 or earlier are affected. No other vendors or products are listed as impacted by this CVE.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability is considered moderate to high severity. The EPSS score is not publicly available, but the unauthenticated nature of the flaw means any visitor can exploit it via the plugin’s input paths. The vulnerability is not currently listed in the CISA KEV catalog, yet it has been publicly disclosed and could be actively targeted by attackers. The likely attack vector involves unauthenticated submission of crafted input that bypasses the plugin’s sanitization routines, resulting in script execution in browsers of site visitors.
OpenCVE Enrichment