PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-42712 QODE CVE debrief

A SQL injection vulnerability exists in Qode Tours plugin versions up to 3.1.3.2. This issue allows a subscriber to inject malicious SQL code. The vulnerability has a CVSS score of 8.5, indicating high severity.

Vendor
QODE
Product
Qode Tours
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for WordPress installations with the Qode Tours plugin should assess exposure and prioritize patching or mitigation efforts.

Why it matters

CVE-2026-42712 is a high-severity SQL injection vulnerability in the Qode Tours WordPress plugin. Defenders should prioritize verifying exposure and applying patches or mitigations to prevent subscriber-based SQL injection attacks.

  • Subscriber roles may be able to inject malicious SQL code, potentially leading to data breaches
  • Successful exploitation could result in unauthorized data access or modification
  • Defenders need to verify exposure and apply patches or mitigations to prevent exploitation
  • SQL injection attacks may be detectable through monitoring of database queries

Technical summary

The Qode Tours plugin up to version 3.1.3.2 is vulnerable to SQL injection attacks. This vulnerability allows a subscriber to inject malicious SQL code, potentially leading to data breaches or system compromise.

Defensive priority

Defenders should prioritize verifying exposure and applying patches or mitigations.

Recommended defensive actions

  • Verify exposure by checking installed plugin versions
  • Apply patches or updates to Qode Tours plugin
  • Monitor for suspicious SQL queries
  • Implement additional security measures for subscriber roles

Evidence notes

The vulnerability was reported by Patchstack and is tracked as CVE-2026-42712. The NVD entry is currently Received.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-42712 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-42712

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-42712 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42712

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.