Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin has 14 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 14 are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 4 high. 2024 was the busiest year with 7 disclosures.

The most common weakness is Missing Authorization, behind 5 of the records (36%). Other recurring categories include SQL Injection, Cross-Site Scripting.

Every one of the 14 issues recorded for Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin has a vendor fix available, so running the current release closes all known holes.

9 independent researchers contributed these findings, most of them (4) reported by LVT-tholv2k.

01234567891018.03.2024Today18.03.20246.1Tourfic <= 2.11.7 - Reflected Cross-Site Scripting CVSS 6.1 · 18.03.20248.8Tourfic <= 2.11.17 - Authenticated (Subscriber+) PHP Object Injection CVSS 8.8 · 18.03.20248.8Tourfic <= 2.11.15 - Authenticated (Subscriber+) Arbitrary File Upload CVSS 8.8 · 18.03.20246.4Tourfic <= 2.11.8 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 18.03.202429.08.20244.3Tourfic <= 2.11.20 - Cross-Site Request Forgery in Multiple Functions CVSS 4.3 · 29.08.202413.09.20244.3Tourfic <= 2.14.5 - Missing Authorization in Multiple Functions CVSS 4.3 · 13.09.202424.12.20246.5Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking <= 2.15.3 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 24.12.202424.01.20257.2Tourfic <= 2.15.3 - Authenticated (Admin+) Arbitrary File Upload CVSS 7.2 · 24.01.202528.03.20265.3Tourfic <= 2.21.4 - Missing Authorization CVSS 5.3 · 28.03.202624.06.20267.5Tourfic <= 2.22.7 - Unauthenticated SQL Injection via 'post_id' Parameter CVSS 7.5 · 24.06.202625.06.20266.5Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.22.5 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 25.06.202608.07.20265.3Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.22.5 - Missing Authorization CVSS 5.3 · 08.07.20264.3Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.22.5 - Missing Authorization CVSS 4.3 · 08.07.202611.08.20264.3Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.23.1 - Missing Authorization CVSS 4.3 · 11.08.2026

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

14

Get automatic notifications for all Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2024-29136

Tourfic <= 2.11.17 - Authenticated (Subscriber+) PHP Object Injection

Read the full analysis

Vulnerability Records

14 records
2026-08-11 00:00CVE-2026-27999
4.3
Medium
Artus KGYes
2026-07-08 00:00CVE-2026-57392
5.3
Medium
RamshathYes
2026-07-08 00:00CVE-2026-57395
4.3
Medium
Sandesh GawaiYes
2026-06-25 00:00CVE-2026-56064
6.5
Medium
anhcd05Yes
2026-06-24 18:36CVE-2026-12937
7.5
High
Wordfence PRISMYes
2026-03-28 00:00CVE-2026-39543
5.3
Medium
Bao - BlueRockYes
2025-01-24 00:00CVE-2025-24650
7.2
High
I8BLYes
2024-12-24 00:00CVE-2024-12032
6.5
Medium
Thái AnYes
2024-09-13 00:00CVE-2024-8860
4.3
Medium
AnonymousYes
2024-08-29 00:00CVE-2024-8319
4.3
Medium
AnonymousYes
Showing 1–10 of 14 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C