CVE-2026-1806 | tourcms Tour & Activity Operator Plugin for TourCMS up to 1.7.0 on WordPress Shortcode tourcms_doc_link target cross site scripting
A vulnerability categorized as problematic has been discovered in tourcms Tour & Activity Operator Plugin for TourCMS up to 1.7.0 on WordPress. The impacted element is the function tourcms_doc_link of the component Shortcode Handler. Executing a manipulation of the argument target can lead to cross site scripting.
This vulnerability is registered as CVE-2026-1806. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.