CVE-2026-28166: WordPress Tourmaster plugin <= 5.4.9 - Cross Site Scripting (XSS) vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
Affected Software
1 affected component
wordpress/tourmaster<=5.4.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Tourmaster pluginto a version that resolves this vulnerability.Fixed in 5.4.9
Event History
Aug 24, 2026
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need an account or user interaction to exploit this issue?
No authentication is required. Exploitation requires user interaction, as indicated by the UI:R vector.
2
How can I tell whether my site is affected?
Check the installed Tourmaster plugin version. Versions 5.4.9 and earlier are affected.
3
What is the potential impact of successful exploitation?
The reported CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. Successful XSS may affect a different security authority than the vulnerable component.