Impact
The vulnerability is caused by a missing capability check in the plugin’s save_option() routine, allowing any user to invoke export or reset of the plugin’s configuration. This results in a loss of stored settings and the possibility that configuration data could be exposed through the export function. The weakness is an Authorization flaw (CWE‑862).
Affected Systems
WordPress sites that have installed the Custom Thank You Page for WooCommerce plugin in any version up to 1.1.2 are affected. The vulnerability applies to the entire range of versions from the first release through 1.1.2; no specific sub‑versions beyond 1.1.2 are enumerated.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS is not available, and the issue is not listed in the CISA KEV catalogue. Attackers do not need authentication and only require access to the site’s web interface to exploit the missing permission check, making the vulnerability readily exploitable.
OpenCVE Enrichment