CVE-2026-39543: WordPress Tourfic plugin <= 2.21.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.21.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/tourficto a version that resolves this vulnerability.Fixed in 2.21.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39543?
CVE-2026-39543 has a medium severity due to its potential for unauthorized access.
How do I fix CVE-2026-39543?
To mitigate CVE-2026-39543, update the Themefic Tourfic plugin to version 2.21.5 or later.
What types of systems are affected by CVE-2026-39543?
CVE-2026-39543 affects WordPress installations using Themefic Tourfic plugin versions up to 2.21.4.
What type of vulnerability is CVE-2026-39543?
CVE-2026-39543 is classified as a Broken Access Control vulnerability.
Can CVE-2026-39543 lead to data exposure?
Yes, if exploited, CVE-2026-39543 can potentially allow unauthorized users to access restricted data.