Tourfic <= 2.22.7 - Unauthenticated SQL Injection via 'post_id' Parameter_CVE-2026-12937
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'post_id' parameter in all versions up to, and including, 2.22.7 due to insufficient escaping on the user supplied parameter...