Impact
Themefic's Tourfic WordPress plugin contains a missing authorization flaw that permits users to access privileged functions without proper permissions. The vulnerability enables exploitation of incorrectly configured access control security levels, potentially allowing an attacker to view, modify or delete plugin data and administrative settings. As the flaw operates at the plugin level, the impact is limited to plugin functionality but can indirectly affect site security if sensitive information is managed through Tourfic.
Affected Systems
Any WordPress site running the Tourfic plugin version 2.22.5 or earlier is vulnerable. The issue applies to all builds from the earliest release up to and including 2.22.5, regardless of the hosting environment or site configuration. Both public and private sites that use Tourfic for tours, bookings or related features are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, but the EPSS score of <1% signals that likelihood of exploitation is low not listed in CISA’s KEV catalog administrative interface or crafted requests to leverage the missing authorization. Because the flaw is a broken access control, authentication may or may not be required; the description suggests the issue arises from incorrectly configured security levels, so even users with limited roles could potentially gain elevated access.
OpenCVE Enrichment