Description
Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a missing authorization flaw that allows attackers to exploit incorrectly configured access control security levels within the Themefic Tourfic plugin for WordPress. The broken access control can let unauthorized users perform privileged actions intended for higher‑privilege accounts, potentially exposing or modifying sensitive data or site content. The weakness is classified as CWE‑862, insufficient authorization.

Affected Systems

All installations of the Themefic Tourfic plugin for WordPress at version 2.22.5 or earlier are affected. The issue applies to any WordPress site that has the Tourfic plugin enabled, regardless of the site's overall configuration or other installed plugins.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote through the web interface, inferred from the plugin’s administrative UI, and the flaw arises because access control checks are insufficient.

Generated by OpenCVE AI on July 31, 2026 at 12:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for the latest Tourfic version and upgrade if it includes an access control fix.
  • Temporarily disable or uninstall the Tourfic plugin until a patched version is available.
  • Restrict WordPress user role permissions so that only trusted administrators can access or configure Tourfic.
  • Audit Tourfic logs for anomalous activity to identify unauthorized access attempts.

Generated by OpenCVE AI on July 31, 2026 at 12:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Themefic
Themefic tourfic
Wordpress
Wordpress wordpress
Vendors & Products Themefic
Themefic tourfic
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.
Title WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Themefic Tourfic
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:53.244Z

Reserved: 2026-06-24T12:46:07.752Z

Link: CVE-2026-57395

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses