Impact
This vulnerability is a missing authorization flaw that permits an attacker to bypass access controls in the Thank You Page Customizer for WooCommerce plugin. The flaw enables unauthorized users to view and edit configuration options that should only be accessed by privileged users. An attacker could thereby alter thank‑you page content, redirect to malicious sites, or otherwise disrupt normal e‑commerce operations. The resulting impact could include defacement, phishing, or loss of customer trust. Based on the description, it is inferred that an attacker could modify thank‑you page behavior to achieve these outcomes.
Affected Systems
The vulnerability affects VillaTheme's Thank You Page Customizer for WooCommerce plugin, from an unspecified initial release up through 1.1.7. No versions newer than 1.1.7 are known to be affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity risk, while the EPSS score of <1% suggests the probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors are web‑based; an attacker can craft HTTP requests to the plugin's back‑end administrative endpoints to exploit the broken access control. While an authenticated or known user is not required, any user who can reach the site is a potential vector, raising the risk for publicly hosted websites.
OpenCVE Enrichment
EUVD