Junglewise Threat Intelligence

CVE-2026-57395: Themefic Tourfic missing authorization in WordPress plugin

CVE-2026-57395 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Technologies: Themefic Tourfic. Vendors: Themefic.

Executive brief

Themefic Tourfic, a WordPress plugin used for managing hotel and tour bookings, contains a security flaw that fails to properly verify user permissions. This allows logged-in users with low-level access, such as customers, to perform actions or access data they should not be authorized to see. An exploit could lead to the exposure of sensitive booking information or unauthorized changes to site configurations.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Themefic Tourfic plugin for WordPress through version 2.22.5. The flaw stems from incorrectly configured access control security levels within the plugin's functional logic. An attacker authenticated with low-level privileges (such as a 'Subscriber' or 'Customer' role) can exploit this to execute functions or access data intended for higher-privileged users. The vulnerability is reachable over the network without user interaction. A fix is available in version 2.22.6.

Affected products

  • Themefic Tourfic <= 2.22.5

Timeline

  • 2026-06-14: other: Reported by researcher Sandesh Gawai
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: CVE published to NVD
  • 2026-07-13: patched: Patch confirmed available in version 2.22.6

References

Related threats