Impact
The vulnerability is a missing authorization flaw that allows users to access restricted functionality of the Tourfic plugin without proper permission checks. It enables potential unauthorized data exposure or modification within the plugin’s features. The weakness falls under CWE‑862, indicating a failure to enforce access controls.
Affected Systems
All releases of the WordPress Tourfic plugin from the earliest version through version 2.21.4 are affected. Users operating any of these versions without a vendor‑issued fix remain vulnerable.
Risk and Exploitability
The CVSS score of 5.3 reflects medium severity, while an EPSS score of less than 1% signals a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. The most probable attack vector involves an attacker exploiting insufficient authorization in the plugin’s administrative or API endpoints; the description does not specify exact prerequisites, so this is an inference based on typical plugin behavior.
OpenCVE Enrichment