CVE-2026-28166

WordPress Tourmaster plugin <= 5.4.9 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.


We have discovered 1,604 live websites that are affected by CVE-2026-28166.

Run a Free Instant Scan




Affected Software

Product  Tour Master
Category Wordpress Plugins
Vulnerable Domains1,604 live websites (100% of Tour Master install base)
Vulnerable Versions
  • from 0 through 5.4.9
Vulnerable Versions Count2 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 24, 2026
  • Updated - Aug 24, 2026

Credits

  • dutafi | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-28166
United States470 websites



Germany139 websites
Italy82 websites
GB79 websites
France71 websites
Cyprus60 websites
India56 websites
Spain47 websites
Turkey43 websites
Greece31 websites

Website Distribution by TLD

Number of websites using CVE-2026-28166
.com1,060 websites
.it43 websites
.com.br27 websites
.co.uk26 websites
.org20 websites
.de19 websites
.net18 websites
.com.au17 websites
.pl16 websites
.nl15 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-28166

Top websites that are affected by CVE-2026-28166. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.com Turkey**,***
*************.com United States***,***
***************.com United States***,***
***********.*********.eu France***,***
****************.org United States***,***
************.***.au Australia***,***
************.com United States***,***
*********.com Thailand***,***
*************.de Germany***,***
**********.gr Greece***,***
See full domain list

FAQ

CVE-2026-28166 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Tour Master
A total of 1,604 websites have been identified as vulnerable to CVE-2026-28166, based on global website indexing conducted by WebTechSurvey.
The Tour Master is affected by the CVE-2026-28166 vulnerability.
Tour Master versions up to and including 5.4.9 are vulnerable to CVE-2026-28166.