Junglewise Threat Intelligence

CVE-2026-57392: Themefic Tourfic missing authorization in access control

CVE-2026-57392 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Technologies: Themefic Tourfic. Vendors: Themefic.

Executive brief

Themefic Tourfic, a WordPress plugin used for building hotel and travel booking websites, contains a security flaw in its access control system. An unauthorized user could exploit this to perform actions they should not be allowed to, potentially disrupting site operations or modifying booking-related information. This could lead to unauthorized changes in site content or service availability.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Themefic Tourfic plugin for WordPress through version 2.22.5. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this lack of enforcement to perform unauthorized actions on the site. The vulnerability is addressed in version 2.22.6.

Affected products

  • Themefic Tourfic <= 2.22.5

Timeline

  • 2026-06-04: other: Reported by researcher Ramshath
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: CVE published to NVD
  • 2026-07-13: patched: Fixed in version 2.22.6

References

Related threats