Extension WordPress

Vulnérabilités Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Cette page rassemble les failles publiées pour Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

13Vulnérabilités
0Critiques
13Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

13 fiches

CVE-2026-57392 Moyenne · 5,3
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.22.5 – Missing Authorization

The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.22.5.…

Versions affectées

*-2.22.5

Correctif

2.22.6

Publication

08/07/2026

CVE-2026-57395 Moyenne · 4,3
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.22.5 – Missing Authorization

The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.22.5.…

Versions affectées

*-2.22.5

Correctif

2.22.6

Publication

08/07/2026

CVE-2026-56064 Moyenne · 6,5
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.22.5 – Authenticated (Subscriber+) SQL Injection

The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.22.5 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-2.22.5

Correctif

2.22.6

Publication

25/06/2026

CVE-2026-12937 Élevée · 7,5
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Tourfic <= 2.22.7 – Unauthenticated SQL Injection via 'post_id' Parameter

The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'post_id' parameter in all versions up to, and including, 2.22.7 due to insufficient…

Versions affectées

*-2.22.7

Correctif

2.22.8

Publication

24/06/2026

CVE-2026-39543 Moyenne · 5,3
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Tourfic <= 2.21.4 – Missing Authorization

The Tourfic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.21.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Versions affectées

*-2.21.4

Correctif

2.21.5

Publication

28/03/2026

CVE-2025-24650 Élevée · 7,2
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Tourfic <= 2.15.3 – Authenticated (Admin+) Arbitrary File Upload

The Tourfic – Ultimate Hotel Booking, Travel Booking & Car Rental WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including,…

Versions affectées

*-2.15.3

Correctif

2.15.4

Publication

24/01/2025

CVE-2024-12032 Moyenne · 6,5
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking <= 2.15.3 – Authenticated (Subscriber+) SQL Injection

The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to SQL Injection via the 'enquiry_id' parameter of the 'tf_enquiry_reply_email_callback' function in all versions up to, and…

Versions affectées

*-2.15.3

Correctif

2.15.4

Publication

24/12/2024

CVE-2024-8860 Moyenne · 4,3
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Tourfic <= 2.14.5 – Missing Authorization in Multiple Functions

The Tourfic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tf_order_status_email_resend_function, tf_visitor_details_edit_function, tf_checkinout_details_edit_function, tf_order_status_edit_function, tf_order_bulk_action_edit_function, tf_remove_room_order_ids, and tf_delete_old_review_fields functions in all versions up to, and including, 2.14.5. This…

Versions affectées

*-2.14.5

Correctif

2.15.0

Publication

13/09/2024

CVE-2024-8319 Moyenne · 4,3
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Tourfic <= 2.11.20 – Cross-Site Request Forgery in Multiple Functions

The Tourfic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.11.20. This is due to missing or incorrect nonce validation on the tf_order_status_email_resend_function, tf_visitor_details_edit_function, tf_checkinout_details_edit_function, tf_order_status_edit_function, tf_order_bulk_action_edit_function, tf_remove_room_order_ids, and tf_delete_old_review_fields…

Versions affectées

*-2.11.20

Correctif

2.11.21

Publication

29/08/2024

CVE-2024-29134 Moyenne · 6,4
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Tourfic <= 2.11.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Tourfic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.11.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-2.11.8

Correctif

2.11.9

Publication

18/03/2024

CVE-2024-29135 Élevée · 8,8
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Tourfic <= 2.11.15 – Authenticated (Subscriber+) Arbitrary File Upload

The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including,…

Versions affectées

*-2.11.15

Correctif

2.11.16

Publication

18/03/2024

CVE-2024-29136 Élevée · 8,8
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Tourfic <= 2.11.17 – Authenticated (Subscriber+) PHP Object Injection

The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.17 via deserialization of untrusted input…

Versions affectées

*-2.11.17

Correctif

2.11.19

Publication

18/03/2024

CVE-2024-29137 Moyenne · 6,1
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Tourfic <= 2.11.7 – Reflected Cross-Site Scripting

The Tourfic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.11.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…

Versions affectées

*-2.11.7

Correctif

2.11.8

Publication

18/03/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités