Description
Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Themefic's Tourfic WordPress plugin contains a missing authorization flaw that permits users to access privileged functions without proper permissions. The vulnerability enables exploitation of incorrectly configured access control security levels, potentially allowing an attacker to view, modify or delete plugin data and administrative settings. As the flaw operates at the plugin level, the impact is limited to plugin functionality but can indirectly affect site security if sensitive information is managed through Tourfic.

Affected Systems

Any WordPress site running the Tourfic plugin version 2.22.5 or earlier is vulnerable. The issue applies to all builds from the earliest release up to and including 2.22.5, regardless of the hosting environment or site configuration. Both public and private sites that use Tourfic for tours, bookings or related features are affected.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, but the EPSS score of <1% signals that likelihood of exploitation is low not listed in CISA’s KEV catalog administrative interface or crafted requests to leverage the missing authorization. Because the flaw is a broken access control, authentication may or may not be required; the description suggests the issue arises from incorrectly configured security levels, so even users with limited roles could potentially gain elevated access.

Generated by OpenCVE AI on July 31, 2026 at 12:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Tourfic to the latest version that includes the access-control fix.
  • If the plugin cannot be updated immediately, either disable the Tourfic plugin or restrict its file permissions to prevent unauthenticated access.
  • Review and correct the Tourfic security settings to ensure only intended roles can perform administrative actions.

Generated by OpenCVE AI on July 31, 2026 at 12:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Themefic
Themefic tourfic
Wordpress
Wordpress wordpress
Vendors & Products Themefic
Themefic tourfic
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.
Title WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Themefic Tourfic
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:39:17.897Z

Reserved: 2026-06-24T12:46:07.752Z

Link: CVE-2026-57392

cve-icon Vulnrichment

Updated: 2026-07-13T14:00:10.611Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses