PT-2026-52215 · WordPress · Tourfic

·

CVE-2026-12937

·

Published

2026-06-25

·

Updated

2026-06-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin versions prior to 2.22.8
Description The plugin is subject to a generic SQL Injection, a flaw where an attacker can interfere with the queries that an application makes to its database. Unauthenticated attackers can append additional SQL queries to existing ones to extract sensitive information from the database. This is possible due to insufficient escaping of user-supplied input and a lack of proper preparation of the SQL query. The issue is reachable via the wp ajax nopriv tf room availability AJAX handler using the post id parameter. Attackers can obtain the required nonce from the public single-hotel page template to access the vulnerable code path.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the post id parameter within the wp ajax nopriv tf room availability handler or disable the plugin until a patch is available.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12937

Affected Products

Tourfic