SQL Injection Vulnerability in Tour Master Travel Plugin for WordPress
CVE-2024-13369
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 February 2025
What is CVE-2024-13369?
The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress has a vulnerability that allows for time-based SQL injection via the âreview_idâ parameter. This issue arises from inadequate escaping of user-supplied input and insufficiently prepared SQL queries. As a result, authenticated attackers with Subscriber-level access or higher can inject malicious SQL code, potentially leading to unauthorized data extraction from the database. Users are urged to ensure their version is updated to mitigate risks associated with this vulnerability.
Affected Version(s)
Tour Master - Tour Booking, Travel, Hotel * <= 5.3.6