Executive brief
Tourfic, a WordPress plugin used for building hotel and tour booking websites, contains a security vulnerability that allows users with basic 'Subscriber' accounts to perform unauthorized database queries. An attacker could exploit this to steal sensitive information from the website's database, potentially including customer details or site configuration. This vulnerability is considered high priority as it could be used in automated attacks against many websites simultaneously.
Technical details
A SQL injection vulnerability exists in the Themefic Tourfic plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to authenticated users with at least 'Subscriber' privileges. By sending specially crafted requests, a remote attacker can bypass intended query logic to interact directly with the underlying database. This can lead to unauthorized data exfiltration or limited impact on database availability. The issue is resolved in version 2.22.6.
Affected products
- Themefic Tourfic <= 2.22.5
Timeline
- 2026-05-20: other: Vulnerability reported by researcher anhcd05
- 2026-06-25: advisory: Patchstack advisory published
- 2026-06-26: disclosed: NVD publication date