SQL Injection Vulnerability in Tourfic AI Powered Travel Booking Plugin for WordPress
CVE-2026-12937

7.5HIGH

What is CVE-2026-12937?

The Tourfic plugin for WordPress is susceptible to SQL Injection through the 'post_id' parameter, affecting all versions up to and including 2.22.7. This vulnerability arises from inadequate escaping of user-supplied data and a poorly prepared SQL query, enabling unauthenticated users to insert arbitrary SQL queries. The AJAX handler's accessibility for unauthenticated users further exacerbates the risk, as it allows attackers to obtain a valid nonce, thereby facilitating unauthorized access to sensitive database information.

Affected Version(s)

Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin 0 <= 2.22.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PRISM
.