Executive brief
Themefic Tourfic, a WordPress plugin used for managing hotel and tour bookings, contains a security flaw in its access control system. This vulnerability allows unauthorized individuals to bypass security checks and potentially access information or perform actions that should be restricted to administrators. An exploit could lead to unauthorized data exposure or interference with booking operations.
Technical details
The Themefic Tourfic plugin for WordPress (versions up to and including 2.21.4) is vulnerable to broken access control due to missing authorization checks (CWE-862). The flaw resides in incorrectly configured access control security levels, which fails to validate the permissions of a user before executing certain functions. An unauthenticated remote attacker can exploit this by sending crafted requests to the affected site, potentially allowing them to execute actions or access data intended for higher-privileged users. The issue is resolved in version 2.21.5.
Affected products
- Themefic Tourfic <= 2.21.4
Timeline
- 2026-02-26: other: Reported by Bao - BlueRock
- 2026-03-28: advisory: Patchstack advisory published
- 2026-04-08: disclosed: CVE published
- 2026-04-08: patched: Patch available in version 2.21.5