Reflected XSS Vulnerability in Tourmaster Plugin by NotFound
CVE-2025-32923
7.1HIGH
What is CVE-2025-32923?
The Tourmaster plugin by NotFound is vulnerable to a reflected cross-site scripting (XSS) issue. This vulnerability allows attackers to inject malicious scripts into web pages viewed by users, potentially compromising user data and enabling various forms of cyberattacks. Secure your site by patching affected versions immediately.
Affected Version(s)
Tourmaster < 5.4.1
