Impact
Improper Control of Generation of Code allows an attacker to inject arbitrary code into the checkout thank you page rendered by the VillaTheme Thank You Page Customizer for WooCommerce plugin. When a user visits the modified page, the injected code can execute in the victim’s browser, potentially leading to user credential theft, defacement, or further malicious actions. In the worst case, if the injection allows execution of server‑side code, an attacker could fully compromise the site’s code base.
Affected Systems
The vulnerability affects the VillaTheme Thank You Page Customizer for WooCommerce plugin versions up to and including 1.2.3 on WordPress installations. Version 1.2.4 and later contain the fix.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. Ephemerally, no EPSS value is available, indicating the exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, so no publicly known exploits have been reported yet. The likely attack vector is through an authenticated administrator who can configure the thank‑you page content; however, the description does not explicitly state the precise conditions, so the exact vector remains inferred.
OpenCVE Enrichment