CVE-2026-27999
- EPSS 0.33%
- Veröffentlicht 13.08.2026 13:36:22
- Zuletzt bearbeitet 14.08.2026 19:09:20
Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.
CVE-2026-57392
- EPSS 0.24%
- Veröffentlicht 13.07.2026 08:41:24
- Zuletzt bearbeitet 13.07.2026 16:57:56
Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.
CVE-2026-57395
- EPSS 0.25%
- Veröffentlicht 13.07.2026 08:41:24
- Zuletzt bearbeitet 13.07.2026 17:17:48
Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.
CVE-2026-56064
- EPSS 0.27%
- Veröffentlicht 26.06.2026 14:52:50
- Zuletzt bearbeitet 26.06.2026 18:17:03
Subscriber SQL Injection in Tourfic <= 2.22.5 versions.
CVE-2026-12937
- EPSS 0.3%
- Veröffentlicht 25.06.2026 06:51:34
- Zuletzt bearbeitet 25.06.2026 17:16:38
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'post_id' parameter in all versions up to, and including, 2.22.7 due to insufficient escaping on ...
CVE-2026-39543
- EPSS 0.22%
- Veröffentlicht 08.04.2026 08:30:17
- Zuletzt bearbeitet 24.07.2026 21:10:00
Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.21.4.
CVE-2024-8860
- EPSS 0.25%
- Veröffentlicht 26.08.2025 07:15:33
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Tourfic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tf_order_status_email_resend_function, tf_visitor_details_edit_function, tf_checkinout_details_edit_function, tf_order_statu...
CVE-2025-24650
- EPSS 0.64%
- Veröffentlicht 24.01.2025 18:15:39
- Zuletzt bearbeitet 23.04.2026 15:25:13
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic allows Upload a Web Shell to a Web Server.This issue affects Tourfic: from n/a through <= 2.15.3.
CVE-2024-12032
- EPSS 0.52%
- Veröffentlicht 25.12.2024 04:15:05
- Zuletzt bearbeitet 05.06.2025 15:32:16
The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to SQL Injection via the 'enquiry_id' parameter of the 'tf_enquiry_reply_email_callback' function in al...
CVE-2024-29136
- EPSS 0.63%
- Veröffentlicht 19.03.2024 14:15:09
- Zuletzt bearbeitet 23.04.2026 15:18:08
Deserialization of Untrusted Data vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.17.