Impact
The Travelfic Toolkit plugin implements role‑based access controls for certain features. In versions 1.5.1 and earlier, the checks that enforce that only administrators can execute privileged operations are bypassed, allowing any subscribed user to invoke those functions. This broken access control (CWE‑862) permits a normal subscriber to modify or delete content, view restricted data, or otherwise perform actions that should be reserved for higher‑privileged users, leading to potential data tampering, disclosure and disruption.
Affected Systems
The vulnerability affects the themefic Travelfic Toolkit WordPress plugin, version 1.5.1 and all earlier releases. Any website running this plugin on WordPress is susceptible unless the plugin has been updated beyond 1.5.1.
Risk and Exploitability
The CVSS score of 8.1 indicates a high‑severity flaw. Although EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, the flaw’s nature means an attacker with a Subscriber role could exploit it by simply sending crafted HTTP requests to the plugin’s endpoints. No specialized conditions are required beyond normal authenticated access within the site.
OpenCVE Enrichment