The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken from a request parameter, and does not escape that label when echoing it on the filter admin page, allowing an unauthenticated attacker to trick a logged-in administrator into storing JavaScript that then executes in the admin area (stored Cross-Site Scripting via CSRF).
We have discovered 1,665 live websites that are affected by CVE-2026-14239.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,665 live websites (100% of Tour Master install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 2 versions ( 100% of all versions) |
| 485 websites | |
| 151 websites | |
| 85 websites | |
| 82 websites | |
| 80 websites | |
| 61 websites | |
| 59 websites | |
| 50 websites | |
| 47 websites | |
| 33 websites |
| .com | 1,099 websites |
| .it | 44 websites |
| .com.br | 29 websites |
| .co.uk | 28 websites |
| .de | 22 websites |
| .net | 19 websites |
| .org | 19 websites |
| .pl | 16 websites |
| .com.au | 16 websites |
| .nl | 15 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****************.com | **,*** | ||
| *************.com | ***,*** | ||
| ***************.com | ***,*** | ||
| ***********.*********.eu | ***,*** | ||
| ****************.org | ***,*** | ||
| ************.***.au | ***,*** | ||
| ************.com | ***,*** | ||
| *********.com | ***,*** | ||
| *************.de | ***,*** | ||
| **********.gr | ***,*** |
FAQ