Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.23.1 - Missing Authorization
medium
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.23.1. This makes it possible for authenticated attackers, with subscriber-level access and ab...
- CVSS:
- 4.3
- Affected:
- up to 2.23.1
- Fixed in:
- 2.23.2
- Disclosed:
- Aug 11, 2026
CVE-2026-27999 on NVD →
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.22.5 - Missing Authorization
medium
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.22.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.22.5
- Fixed in:
- 2.22.6
- Disclosed:
- Jul 8, 2026
CVE-2026-57392 on NVD →
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.22.5 - Missing Authorization
medium
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.22.5. This makes it possible for authenticated attackers, with customer-level access and abov...
- CVSS:
- 4.3
- Affected:
- up to 2.22.5
- Fixed in:
- 2.22.6
- Disclosed:
- Jul 8, 2026
CVE-2026-57395 on NVD →
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.22.5 - Authenticated (Subscriber+) SQL Injection
medium
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.22.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possib...
- CVSS:
- 6.5
- Affected:
- up to 2.22.5
- Fixed in:
- 2.22.6
- Disclosed:
- Jun 25, 2026
CVE-2026-56064 on NVD →
Tourfic <= 2.22.7 - Unauthenticated SQL Injection via 'post_id' Parameter
high
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'post_id' parameter in all versions up to, and including, 2.22.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...
- CVSS:
- 7.5
- Affected:
- up to 2.22.7
- Fixed in:
- 2.22.8
- Disclosed:
- Jun 24, 2026
CVE-2026-12937 on NVD →
Tourfic <= 2.21.4 - Missing Authorization
medium
The Tourfic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.21.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.21.4
- Fixed in:
- 2.21.5
- Disclosed:
- Mar 28, 2026
CVE-2026-39543 on NVD →
Tourfic <= 2.15.3 - Authenticated (Admin+) Arbitrary File Upload
high
The Tourfic – Ultimate Hotel Booking, Travel Booking & Car Rental WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.15.3. This makes it possible for authenticated attackers, with Administrator-l...
- CVSS:
- 7.2
- Affected:
- up to 2.15.3
- Fixed in:
- 2.15.4
- Disclosed:
- Jan 24, 2025
CVE-2025-24650 on NVD →
Tourfic – Ultimate Travel Booking, Hotel Booking & Car Rental WordPress Plugin | WooCommerce Booking [tourfic] < 2.15.4
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic allows Upload a Web Shell to a Web Server. This issue affects Tourfic: from n/a through 2.15.3.
- Affected:
- up to 2.15.4
- Fixed in:
- 2.15.4
- Disclosed:
- Jan 24, 2025
CVE-2025-24650 on NVD →
Tourfic – Ultimate Travel Booking, Hotel Booking & Car Rental WordPress Plugin | WooCommerce Booking [tourfic] < 2.15.4
unknown
[en] The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to SQL Injection via the 'enquiry_id' parameter of the 'tf_enquiry_reply_email_callback' function in all versions up to, and including, 2.15.3 due to insufficient escap...
- Affected:
- up to 2.15.4
- Fixed in:
- 2.15.4
- Disclosed:
- Dec 25, 2024
CVE-2024-12032 on NVD →
Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking <= 2.15.3 - Authenticated (Subscriber+) SQL Injection
medium
The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to SQL Injection via the 'enquiry_id' parameter of the 'tf_enquiry_reply_email_callback' function in all versions up to, and including, 2.15.3 due to insufficient escaping o...
- CVSS:
- 6.5
- Affected:
- up to 2.15.3
- Fixed in:
- 2.15.4
- Disclosed:
- Dec 24, 2024
CVE-2024-12032 on NVD →
Tourfic <= 2.14.5 - Missing Authorization in Multiple Functions
medium
The Tourfic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tf_order_status_email_resend_function, tf_visitor_details_edit_function, tf_checkinout_details_edit_function, tf_order_status_edit_function, tf_order_bulk_action_edit_function, tf_remove_room_or...
- CVSS:
- 4.3
- Affected:
- up to 2.14.5
- Fixed in:
- 2.15.0
- Disclosed:
- Sep 13, 2024
CVE-2024-8860 on NVD →
Tourfic – Ultimate Travel Booking, Hotel Booking & Car Rental WordPress Plugin | WooCommerce Booking [tourfic] < 2.11.21
unknown
[en] The Tourfic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.11.20. This is due to missing or incorrect nonce validation on the tf_order_status_email_resend_function, tf_visitor_details_edit_function, tf_checkinout_details_edit_function, tf_order_status_edit...
- Affected:
- up to 2.11.21
- Fixed in:
- 2.11.21
- Disclosed:
- Aug 30, 2024
CVE-2024-8319 on NVD →
Tourfic <= 2.11.20 - Cross-Site Request Forgery in Multiple Functions
medium
The Tourfic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.11.20. This is due to missing or incorrect nonce validation on the tf_order_status_email_resend_function, tf_visitor_details_edit_function, tf_checkinout_details_edit_function, tf_order_status_edit_func...
- CVSS:
- 4.3
- Affected:
- up to 2.11.20
- Fixed in:
- 2.11.21
- Disclosed:
- Aug 29, 2024
CVE-2024-8319 on NVD →
Tourfic – Ultimate Travel Booking, Hotel Booking & Car Rental WordPress Plugin | WooCommerce Booking [tourfic] < 2.11.16
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Tourfic.This issue affects Tourfic: from n/a through 2.11.15.
- Affected:
- up to 2.11.16
- Fixed in:
- 2.11.16
- Disclosed:
- Mar 19, 2024
CVE-2024-29135 on NVD →
Tourfic – Ultimate Travel Booking, Hotel Booking & Car Rental WordPress Plugin | WooCommerce Booking [tourfic] < 2.11.8
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic allows Reflected XSS.This issue affects Tourfic: from n/a through 2.11.7.
- Affected:
- up to 2.11.8
- Fixed in:
- 2.11.8
- Disclosed:
- Mar 19, 2024
CVE-2024-29137 on NVD →
Tourfic – Ultimate Travel Booking, Hotel Booking & Car Rental WordPress Plugin | WooCommerce Booking [tourfic] < 2.11.19
unknown
[en] Deserialization of Untrusted Data vulnerability in Themefic Tourfic.This issue affects Tourfic: from n/a through 2.11.17.
- Affected:
- up to 2.11.19
- Fixed in:
- 2.11.19
- Disclosed:
- Mar 19, 2024
CVE-2024-29136 on NVD →
Tourfic – Ultimate Travel Booking, Hotel Booking & Car Rental WordPress Plugin | WooCommerce Booking [tourfic] < 2.11.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic allows Stored XSS.This issue affects Tourfic: from n/a through 2.11.8.
- Affected:
- up to 2.11.9
- Fixed in:
- 2.11.9
- Disclosed:
- Mar 19, 2024
CVE-2024-29134 on NVD →
Tourfic <= 2.11.15 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.11.15. This makes it possible for authenticated attackers, with subscri...
- CVSS:
- 8.8
- Affected:
- up to 2.11.15
- Fixed in:
- 2.11.16
- Disclosed:
- Mar 18, 2024
CVE-2024-29135 on NVD →
Tourfic <= 2.11.17 - Authenticated (Subscriber+) PHP Object Injection
high
The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.17 via deserialization of untrusted input . This makes it possible for authenticated attackers, with subsc...
- CVSS:
- 8.8
- Affected:
- up to 2.11.17
- Fixed in:
- 2.11.19
- Disclosed:
- Mar 18, 2024
CVE-2024-29136 on NVD →
Tourfic <= 2.11.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Tourfic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.11.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.4
- Affected:
- up to 2.11.8
- Fixed in:
- 2.11.9
- Disclosed:
- Mar 18, 2024
CVE-2024-29134 on NVD →
Tourfic <= 2.11.7 - Reflected Cross-Site Scripting
medium
The Tourfic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.11.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- up to 2.11.7
- Fixed in:
- 2.11.8
- Disclosed:
- Mar 18, 2024
CVE-2024-29137 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database