SQL Injection Vulnerability in Tour Master Travel Plugin for WordPress
CVE-2024-13369
8.8HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 18 February 2025
Summary
The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress has a vulnerability that allows for time-based SQL injection via the ‘review_id’ parameter. This issue arises from inadequate escaping of user-supplied input and insufficiently prepared SQL queries. As a result, authenticated attackers with Subscriber-level access or higher can inject malicious SQL code, potentially leading to unauthorized data extraction from the database. Users are urged to ensure their version is updated to mitigate risks associated with this vulnerability.
Affected Version(s)
Tour Master - Tour Booking, Travel, Hotel * <= 5.3.6
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Aiden