๐Ÿ” CVE Alert

CVE-2024-29137

UNKNOWN 0.0

WordPress Tourfic plugin <= 2.11.7 - Reflected Cross Site Scripting (XSS) vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.7.

CWE CWE-79
Vendor themefic
Product tourfic
Published Mar 19, 2024
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for themefic tourfic

Be the first to know when new unknown vulnerabilities affecting themefic tourfic are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Themefic / Tourfic
0 โ‰ค 2.11.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/tourfic/vulnerability/wordpress-tourfic-plugin-2-11-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve patchstack.com: https://patchstack.com/database/vulnerability/tourfic/wordpress-tourfic-plugin-2-11-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve

Credits

LVT-tholv2k | Patchstack Bug Bounty Program