CyberRota Analysis
AI-GeneratedThe tourmaster WordPress plugin prior to version 5.4.9 exposes customer personal information by writing order and booking exports to a publicly accessible directory without proper access controls. This vulnerability allows unauthenticated users to download sensitive data after an administrator performs an export. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.
Original NVD Description
The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated users to download the exported customers' personal information once an administrator has run an export.