Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic allows Upload a Web Shell to a Web Server. This issue affects Tourfic: from n/a through 2.15.3.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-3848 Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic allows Upload a Web Shell to a Web Server. This issue affects Tourfic: from n/a through 2.15.3.
Fixes

Solution

Update the WordPress Tourfic wordpress plugin to the latest available version (at least 2.15.4).


Workaround

No workaround given by the vendor.

History

Mon, 09 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Themefic
Themefic tourfic
CPEs cpe:2.3:a:themefic:tourfic:*:*:*:*:*:wordpress:*:*
Vendors & Products Themefic
Themefic tourfic

Fri, 24 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic allows Upload a Web Shell to a Web Server. This issue affects Tourfic: from n/a through 2.15.3.
Title WordPress Tourfic plugin <= 2.15.3 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2025-01-24T18:58:04.419Z

Reserved: 2025-01-23T14:51:41.777Z

Link: CVE-2025-24650

cve-icon Vulnrichment

Updated: 2025-01-24T18:45:51.204Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-24T18:15:39.347

Modified: 2025-06-09T18:53:22.317

Link: CVE-2025-24650

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.