PatchSiren cyber security CVE debrief
CVE-2026-42712 QODE CVE debrief
A SQL injection vulnerability exists in Qode Tours plugin versions up to 3.1.3.2. This issue allows a subscriber to inject malicious SQL code. The vulnerability has a CVSS score of 8.5, indicating high severity.
- Vendor
- QODE
- Product
- Qode Tours
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations with the Qode Tours plugin should assess exposure and prioritize patching or mitigation efforts.
Why it matters
CVE-2026-42712 is a high-severity SQL injection vulnerability in the Qode Tours WordPress plugin. Defenders should prioritize verifying exposure and applying patches or mitigations to prevent subscriber-based SQL injection attacks.
- Subscriber roles may be able to inject malicious SQL code, potentially leading to data breaches
- Successful exploitation could result in unauthorized data access or modification
- Defenders need to verify exposure and apply patches or mitigations to prevent exploitation
- SQL injection attacks may be detectable through monitoring of database queries
Technical summary
The Qode Tours plugin up to version 3.1.3.2 is vulnerable to SQL injection attacks. This vulnerability allows a subscriber to inject malicious SQL code, potentially leading to data breaches or system compromise.
Defensive priority
Defenders should prioritize verifying exposure and applying patches or mitigations.
Recommended defensive actions
- Verify exposure by checking installed plugin versions
- Apply patches or updates to Qode Tours plugin
- Monitor for suspicious SQL queries
- Implement additional security measures for subscriber roles
Evidence notes
The vulnerability was reported by Patchstack and is tracked as CVE-2026-42712. The NVD entry is currently Received.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42712 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42712
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42712 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42712
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.