SQL Injection Vulnerability in Tour Master Travel Plugin for WordPress
CVE-2024-13369
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 February 2025
What is CVE-2024-13369?
The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress has a vulnerability that allows for time-based SQL injection via the ‘review_id’ parameter. This issue arises from inadequate escaping of user-supplied input and insufficiently prepared SQL queries. As a result, authenticated attackers with Subscriber-level access or higher can inject malicious SQL code, potentially leading to unauthorized data extraction from the database. Users are urged to ensure their version is updated to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Tour Master - Tour Booking, Travel, Hotel * <= 5.3.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved