cleantalk
Vulnerabilities and Security Researches

Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking, CVE-2025-24650

CVE, Research URL

CVE-2025-24650

Published on
Jan 24, 2025
Research Description
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic allows Upload a Web Shell to a Web Server. This issue affects Tourfic: from n/a through 2.15.3.
Affected versions
max 2.15.4.
Status
vulnerable