
CVE-2026-1806 The Tour & Activity Operator Plugin for TourCMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the tourcms_doc_link sho… https://www.cve.org/CVERecord?id=CVE-2026-1806
Post summary
The CVE entry announces a stored XSS vulnerability in the TourCMS WordPress plugin, specifying the affected 'target' parameter, but does not provide proof of exploitation or remediation details.
