Impact
The vulnerability is a broken access control flaw that allows a subscriber or other authenticated user to perform privileged actions normally reserved for higher‑level users. It is classified as CWE‑862, meaning insufficient permission checks exist. If exploited, an attacker could gain unauthorized access to sensitive data or functionality within the Tourfic plugin, leading to confidentiality or integrity violations.
Affected Systems
WordPress sites running the Themefic Tourfic plugin up to and including version 2.23.1 are affected. Any installation using these or earlier versions is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is not available, implying that no current data on exploit probability exists. The vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation evidence to date. Based on the description, the likely attack vector is an authenticated user exploiting the plugin's insufficient permission checks; therefore users with normal subscriber privileges could potentially elevate their access rights.
OpenCVE Enrichment