Junglewise Threat Intelligence

CVE-2025-69133: GoodLayers Tourmaster Local File Inclusion

CVE-2025-69133 · Severity: high · CVSS 7.5 · Published 2026-07-02

Executive brief

Tourmaster, a popular WordPress plugin used for managing tours and bookings, contains a security flaw that allows users with basic 'Subscriber' accounts to access sensitive internal files. An attacker could use this to steal database credentials or other configuration data, potentially leading to a full takeover of the website. No official patch has been released yet, so administrators should monitor the plugin closely or use third-party security mitigations.

Technical details

The Tourmaster plugin for WordPress (versions <= 5.4.5) is vulnerable to Local File Inclusion (LFI) due to improper control of filenames in PHP include/require statements (CWE-98). The vulnerability requires 'Subscriber' level authentication, though the attack complexity is rated as high. An authenticated attacker can exploit this to include and execute local files on the server, potentially leading to the disclosure of sensitive information like wp-config.php or remote code execution if combined with file upload capabilities. As of the advisory date, no official patch is available from the vendor.

Affected products

  • GoodLayers Tourmaster <= 5.4.5

Timeline

  • 2025-10-22: other: Vulnerability reported by researcher João Pedro S Alcântara
  • 2026-06-29: advisory: Initial advisory published by Patchstack
  • 2026-07-02: disclosed: CVE published to NVD dataset

References