Impact
This vulnerability is a missing authorization flaw that allows attackers to exploit incorrectly configured access control security levels within the Themefic Tourfic plugin for WordPress. The broken access control can let unauthorized users perform privileged actions intended for higher‑privilege accounts, potentially exposing or modifying sensitive data or site content. The weakness is classified as CWE‑862, insufficient authorization.
Affected Systems
All installations of the Themefic Tourfic plugin for WordPress at version 2.22.5 or earlier are affected. The issue applies to any WordPress site that has the Tourfic plugin enabled, regardless of the site's overall configuration or other installed plugins.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote through the web interface, inferred from the plugin’s administrative UI, and the flaw arises because access control checks are insufficient.
OpenCVE Enrichment