Input validation vulnerability in Tour Master – Tour Booking, Travel, Hotel 5.3.6

The Tour Master plugin for WordPress, which helps with booking tours, travel, and hotels, has a security vulnerability. This vulnerability allows attackers with Subscriber-level access or higher to add their own SQL queries to existing ones, which could potentially reveal sensitive information from the database. This vulnerability affects all versions up to and including 5.3.6 and is caused by inadequate protection on user-supplied parameters and insufficient preparation on existing SQL queries.

Detected in:

Tour Master - Tour Booking, Travel, Hotel fixed vulnerable versions: >= * <= 5.3.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.