Sceawere
Vulnerability Detail
CVE-2026-39774UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Tourfic Pro Unauthenticated Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 16h ago
- Vendor
- Tourfic AI Studio
- Product
- Tourfic Pro
- Attack Type
- CWE-266 Incorrect Privilege Assignment
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-06T09:17:50.053Z",
"pubdate": "2026-10-06T09:17:50.053Z",
"executiveSummary": "A critical privilege escalation vulnerability exists within Tourfic Pro versions 1.17.3 and below. This security flaw permits unauthenticated remote attackers to manipulate user account privileges without requiring valid credentials or prior authorization.\nThe vulnerability type involves improper authorization controls that allow an attacker to intercept or forge requests to elevate their own account permissions to those of an administrator. By successfully exploiting this flaw, an attacker can gain full administrative access to the WordPress environment, leading to a complete site takeover.\nThe impact includes unauthorized access to sensitive data, modification of site configurations, execution of arbitrary administrative actions, and the potential for persistent backdooring of the server. Given that this vulnerability does not require any prior authentication or special user interaction, it represents a high-risk security threat to organizations utilizing the affected plugin. Systems running Tourfic Pro 1.17.3 or earlier are currently exposed to potential exploitation if the vulnerable endpoints are reachable over the network.",
"technicalDetails": "The root cause of the vulnerability in Tourfic Pro <= 1.17.3 lies in the absence of robust nonce verification or authorization checks within the plugin's internal request handling mechanisms. In many WordPress-based privilege escalation vulnerabilities of this nature, the plugin fails to validate the current user's session or capability levels before executing high-privilege functions, such as those related to user profile updates or user registration role assignment.\nThe attack flow typically begins with an unauthenticated attacker identifying the specific API endpoints or AJAX handlers responsible for processing user metadata updates. Because these endpoints lack server-side permission validation, an attacker can craft a malicious HTTP request—often using a POST method—that includes parameters intended to update the user_role or modify account meta-fields that govern privilege levels. By manipulating these parameters, the attacker can force the application to escalate the privileges of a session or a newly registered user account to 'administrator' or equivalent.\nExploitation does not require elevated privileges; the attacker initiates the request from an unauthenticated state, effectively bypassing the security boundary that prevents regular users or guest visitors from modifying system-level settings. The vulnerable component is likely a registration or profile-update function that improperly trusts user-supplied input to define or upgrade user roles. When the application receives the crafted payload, it fails to perform a capability check (e.g., current_user_can('manage_options')) before updating the database, resulting in the successful modification of the targeted user's role.\nPost-exploitation impact is severe, as an attacker with administrative privileges can install malicious plugins, upload arbitrary web shells, configure unauthorized administrative accounts, and exfiltrate user data. The vulnerability is network-accessible, meaning any remote attacker capable of sending HTTP requests to the target site's REST API or admin-ajax.php interface can initiate the exploit. Because the plugin does not verify the authenticity of the requester through cryptographic tokens (nonces), it cannot distinguish between legitimate administrative actions and unauthorized exploitation attempts, providing the attacker with full control over the application's core functionality."
}