Themefic develops a focused line of WordPress plugins and themes—including contact form extensions, tour-booking tools, and image-gallery solutions—that represent a modest but prominent footprint in the WordPress ecosystem. Vulnerabilities affecting the vendor skew toward serious outcomes and show a moderate tendency toward public exploit availability; the recurring weakness classes of cross-site scripting, unrestricted file uploads, SQL injection, and untrusted deserialization reflect common application-layer risks in server-side web plugins where user input handling and object serialization are critical. Defenders should treat updates to widely installed Themefic plugins as maintenance priorities, especially in shared-hosting environments where a single flaw can affect multiple downstream sites; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themefic over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56064HIGH Subscriber SQL Injection in Tourfic <= 2.22.5 versions. | Jun 26, 2026 | 8.5 | 34 | NO | NO |
CVE-2026-57392MEDIUM Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through | Jul 13, 2026 | 6.5 | 30 | NO | NO |
CVE-2026-57395MEDIUM Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through | Jul 13, 2026 | 6.5 | 27 | NO | NO |
CVE-2024-29137MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11. | Mar 19, 2024 | 6.1 | 27 | NO | YES |
CVE-2022-47586CRITICAL Unauth. SQL Injection (SQLi) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.1.23 versions. | Jun 19, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-24650CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic allows Upload a Web Shell to a Web Server.This issue affects Tourfic: from n/a through <= | Jan 24, 2025 | 9.1 | 26 | NO | NO |
CVE-2024-29136HIGH Deserialization of Untrusted Data vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.17. | Mar 19, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-29135HIGH Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.15. | Mar 19, 2024 | 8.8 | 23 | NO | NO |
CVE-2026-32460MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 | Mar 13, 2026 | 6.5 | 22 | NO | NO |
CVE-2023-30495HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Ultimate Addons for Contact Form 7.This issue affects Ultimate Addons | Dec 20, 2023 | 8.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themefic.
Media articles that mention a CVE ID that affects a product developed by Themefic — matched by CVE ID, not by vendor name.