Impact
The Thank You Page Customizer for WooCommerce plugin fails to verify user privileges before allowing users to modify thank‑you page content. This flaw lets an unauthenticated user alter page text or inject malicious code, potentially defacing the site or facilitating phishing and other attacks.
Affected Systems
VillaTheme's Thank You Page Customizer for WooCommerce, versions 1.2.2 and earlier, is vulnerable. WordPress sites running any of these versions have inadequate access restrictions on the plugin’s customizer functions.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability with a broad attack surface. Although no exploitation probability is publicly available, the flaw is unauthenticated and can be discovered via the web interface, making exploitation likely once discovered. The package is not listed in CISA’s KEV catalog, but that does not diminish the threat since the weakness remains present in all affected releases.
OpenCVE Enrichment