CVE-2024-8860 | Tourfic Plugin up to 2.14.5 on WordPress authorization
A vulnerability was found in Tourfic Plugin up to 2.14.5 on WordPress. It has been rated as critical. Affected by this issue is the function tf_order_status_email_resend_function/tf_visitor_details_edit_function/tf_checkinout_details_edit_function/tf_order_status_edit_function/tf_order_bulk_action_edit_function/tf_remove_room_order_ids/tf_delete_old_review_fields. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2024-8860. The attack is possible to be carried out remotely. No exploit exists.