Description
Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from n/a through 1.2.3.
Published: 2026-10-10
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Code Injection
Action: Apply Patch
AI Analysis

Impact

Improper Control of Generation of Code allows an attacker to inject arbitrary code into the checkout thank you page rendered by the VillaTheme Thank You Page Customizer for WooCommerce plugin. When a user visits the modified page, the injected code can execute in the victim’s browser, potentially leading to user credential theft, defacement, or further malicious actions. In the worst case, if the injection allows execution of server‑side code, an attacker could fully compromise the site’s code base.

Affected Systems

The vulnerability affects the VillaTheme Thank You Page Customizer for WooCommerce plugin versions up to and including 1.2.3 on WordPress installations. Version 1.2.4 and later contain the fix.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. Ephemerally, no EPSS value is available, indicating the exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, so no publicly known exploits have been reported yet. The likely attack vector is through an authenticated administrator who can configure the thank‑you page content; however, the description does not explicitly state the precise conditions, so the exact vector remains inferred.

Generated by OpenCVE AI on October 10, 2026 at 18:22 UTC.

Remediation

Vendor Solution

Update the WordPress Thank You Page Customizer for WooCommerce plugin to the latest available version (at least 1.2.4).


OpenCVE Recommended Actions

  • Update the WordPress Thank You Page Customizer for WooCommerce plugin to version 1.2.4 or later.
  • If an immediate update is not feasible, disable custom content on the thank‑you page or restrict it to sanitized, safe HTML to prevent injection of malicious code.
  • Ensure WordPress core, WooCommerce, and all other plugins are up to date to reduce the overall attack surface.

Generated by OpenCVE AI on October 10, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from n/a through 1.2.3.
Title WordPress Thank You Page Customizer for WooCommerce plugin <= 1.2.3 - Content Injection vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T17:00:10.567Z

Reserved: 2026-09-30T00:15:58.645Z

Link: CVE-2026-103071

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T17:16:59.673

Modified: 2026-10-10T17:16:59.673

Link: CVE-2026-103071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T18:30:08Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')