CVE-2026-42712: WordPress Qode Tours plugin <= 3.1.3.2 - SQL Injection vulnerability
Published Oct 10, 2026
·Updated
Subscriber SQL Injection in Qode Tours <= 3.1.3.2 versions.
Affected Software
1 affected component
Qode Qode Tours<=3.1.3.2
Event History
Oct 10, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is exploitable by an authenticated user with Subscriber-level privileges. It does not require user interaction and has low attack complexity.
2
Is the issue remotely reachable, and what is the potential impact?
The attack vector is network-based, so a qualifying authenticated user could attempt exploitation remotely. Successful exploitation may expose highly sensitive data and can have scope beyond the vulnerable component; availability impact is rated low, while integrity impact is not indicated.