Themefic Vulnerabilities and Affected Products
Vulnerabilities associated with Instantio.
Products
Clear product- Tourfic10 vulnerabilities
- Hydra Booking9 vulnerabilities
- Ultimate Addons for Contact Form 78 vulnerabilities
- Ultra Addons for Contact Form 75 vulnerabilities
- Hydra Booking — Appointment Scheduling & Booking Calendar3 vulnerabilities
- Instantio3 vulnerabilities
- Tourfic – Travel Booking, Hotel Booking & Car Rental WordPress Plugin3 vulnerabilities
- Travelfic Toolkit3 vulnerabilities
- BEAF2 vulnerabilities
- Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings1 vulnerability
- Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin1 vulnerability
- Ultra Addons for WPForms1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-39571MEDIUM | WordPress Instantio plugin <= 3.3.30 - Sensitive Data Exposure vulnerabilityExposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themefic Instantio instantio allows Retrieve Embedded Sensitive Data.This issue affects Instantio: from n/a through <= 3.3.30. CWE-497Apr 8, 2026 | CVSS5.3v3.1 | EPSS0.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-47550MEDIUM | WordPress Instantio plugin <= 3.3.16 - Arbitrary File Upload VulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in Themefic Instantio instantio allows Upload a Web Shell to a Web Server.This issue affects Instantio: from n/a through <= 3.3.16. CWE-434May 7, 2025 | CVSS6.6v3.1 | EPSS0.443% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-24581MEDIUM | WordPress Instantio plugin <= 3.3.7 - Settings Change vulnerabilityMissing Authorization vulnerability in Themefic Instantio instantio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Instantio: from n/a through <= 3.3.7. CWE-862Apr 17, 2025 | CVSS6.5v3.1 | EPSS0.361% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |