Goodlayers develops a focused set of WordPress-based plugins and themes for tour, travel, and learning management functionality, where vulnerabilities cluster in common web-application input-handling weaknesses. Its disclosures skew toward serious outcomes and frequently acquire public exploit code, with the recurring exposure centered on cross-site scripting and SQL injection flaws across products such as Tour Master, Goodlayers Core, and Good Learning Management System. Live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Goodlayers over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27481CRITICAL An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated us | Nov 12, 2020 | 9.8 | 47 | NO | YES |
CVE-2024-13369HIGH The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up to, and including, 5.3 | Feb 18, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-12400HIGH The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting. | Jan 30, 2025 | 7.1 | 19 | NO | NO |
CVE-2024-11356MEDIUM The tourmaster WordPress plugin before 5.3.4 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross | Jan 6, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-11357MEDIUM The goodlayers-core WordPress plugin before 2.0.10 does not sanitise and escape some of its settings, which could allow users with the contributor role and above to perform Stored | Jan 2, 2025 | 5.9 | 18 | NO | NO |
CVE-2024-11846MEDIUM The does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users su | Jan 1, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-12163MEDIUM The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads. | Jan 30, 2025 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Goodlayers.
Media articles that mention a CVE ID that affects a product developed by Goodlayers — matched by CVE ID, not by vendor name.