SQL Injection Vulnerability in Tourfic AI Powered Travel Booking Plugin for WordPress
CVE-2026-12937
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 June 2026
What is CVE-2026-12937?
The Tourfic plugin for WordPress is susceptible to SQL Injection through the 'post_id' parameter, affecting all versions up to and including 2.22.7. This vulnerability arises from inadequate escaping of user-supplied data and a poorly prepared SQL query, enabling unauthenticated users to insert arbitrary SQL queries. The AJAX handler's accessibility for unauthenticated users further exacerbates the risk, as it allows attackers to obtain a valid nonce, thereby facilitating unauthorized access to sensitive database information.
Affected Version(s)
Tourfic β AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin 0 <= 2.22.7