CVE Explorer
CVE-2026-14239
The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken from a request parameter, and does not escape that label when echoing it on the filter admin page, allowing an unauthenticated attacker to trick a logged-in administrator into storing JavaScript that then executes in the admin area (stored Cross-Site Scripting via CSRF).
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"description":"CWE-352 Cross-Site Request Forgery (CSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8640574d67218a7511257a67bdc0d8d5556de079f69455531edf0fc5f66a9715 · sha256:7dfb7244907aadc6… · /containers/cna/problemTypes/1/descriptions/0
{"description":"CWE-79 Cross-Site Scripting (XSS)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8640574d67218a7511257a67bdc0d8d5556de079f69455531edf0fc5f66a9715 · sha256:7dfb7244907aadc6… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"tourmaster","vendor":"Unknown","versions":[{"lessThan":"5.4.8","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8640574d67218a7511257a67bdc0d8d5556de079f69455531edf0fc5f66a9715 · sha256:7dfb7244907aadc6… · /containers/cna/affected/0
CWE assertions
2 source assertions{"description":"CWE-352 Cross-Site Request Forgery (CSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8640574d67218a7511257a67bdc0d8d5556de079f69455531edf0fc5f66a9715 · sha256:7dfb7244907aadc6… · /containers/cna/problemTypes/1/descriptions/0
{"description":"CWE-79 Cross-Site Scripting (XSS)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8640574d67218a7511257a67bdc0d8d5556de079f69455531edf0fc5f66a9715 · sha256:7dfb7244907aadc6… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/1cd293c6-10c3-4a5c-914e-b3bdcd316d2b/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8640574d67218a7511257a67bdc0d8d5556de079f69455531edf0fc5f66a9715 · sha256:7dfb7244907aadc6… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.