PT-2026-52215 · WordPress · Tourfic
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin versions prior to 2.22.8
Description
The plugin is subject to a generic SQL Injection, a flaw where an attacker can interfere with the queries that an application makes to its database. Unauthenticated attackers can append additional SQL queries to existing ones to extract sensitive information from the database. This is possible due to insufficient escaping of user-supplied input and a lack of proper preparation of the SQL query. The issue is reachable via the
wp ajax nopriv tf room availability AJAX handler using the post id parameter. Attackers can obtain the required nonce from the public single-hotel page template to access the vulnerable code path.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the
post id parameter within the wp ajax nopriv tf room availability handler or disable the plugin until a patch is available.SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tourfic