Extension WordPress
Vulnérabilités Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin
Cette page rassemble les failles publiées pour Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin
13 fiches
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.22.5 – Missing Authorization
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.22.5.…
*-2.22.5
2.22.6
08/07/2026
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.22.5 – Missing Authorization
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.22.5.…
*-2.22.5
2.22.6
08/07/2026
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.22.5 – Authenticated (Subscriber+) SQL Injection
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.22.5 due to insufficient escaping on the user supplied parameter…
*-2.22.5
2.22.6
25/06/2026
Tourfic <= 2.22.7 – Unauthenticated SQL Injection via 'post_id' Parameter
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'post_id' parameter in all versions up to, and including, 2.22.7 due to insufficient…
*-2.22.7
2.22.8
24/06/2026
Tourfic <= 2.21.4 – Missing Authorization
The Tourfic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.21.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
*-2.21.4
2.21.5
28/03/2026
Tourfic <= 2.15.3 – Authenticated (Admin+) Arbitrary File Upload
The Tourfic – Ultimate Hotel Booking, Travel Booking & Car Rental WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including,…
*-2.15.3
2.15.4
24/01/2025
Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking <= 2.15.3 – Authenticated (Subscriber+) SQL Injection
The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to SQL Injection via the 'enquiry_id' parameter of the 'tf_enquiry_reply_email_callback' function in all versions up to, and…
*-2.15.3
2.15.4
24/12/2024
Tourfic <= 2.14.5 – Missing Authorization in Multiple Functions
The Tourfic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tf_order_status_email_resend_function, tf_visitor_details_edit_function, tf_checkinout_details_edit_function, tf_order_status_edit_function, tf_order_bulk_action_edit_function, tf_remove_room_order_ids, and tf_delete_old_review_fields functions in all versions up to, and including, 2.14.5. This…
*-2.14.5
2.15.0
13/09/2024
Tourfic <= 2.11.20 – Cross-Site Request Forgery in Multiple Functions
The Tourfic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.11.20. This is due to missing or incorrect nonce validation on the tf_order_status_email_resend_function, tf_visitor_details_edit_function, tf_checkinout_details_edit_function, tf_order_status_edit_function, tf_order_bulk_action_edit_function, tf_remove_room_order_ids, and tf_delete_old_review_fields…
*-2.11.20
2.11.21
29/08/2024
Tourfic <= 2.11.8 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Tourfic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.11.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-2.11.8
2.11.9
18/03/2024
Tourfic <= 2.11.15 – Authenticated (Subscriber+) Arbitrary File Upload
The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including,…
*-2.11.15
2.11.16
18/03/2024
Tourfic <= 2.11.17 – Authenticated (Subscriber+) PHP Object Injection
The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.17 via deserialization of untrusted input…
*-2.11.17
2.11.19
18/03/2024
Tourfic <= 2.11.7 – Reflected Cross-Site Scripting
The Tourfic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.11.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-2.11.7
2.11.8
18/03/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.