GHSA-jp8r-42gx-hfwhMediumCVSS 6.5

The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized...

Published
September 24, 2026
Last Modified
September 24, 2026

🔗 CVE IDs covered (1)

📋 Description

The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to export or reset(delete) the plugin's settings.

🔗 References (4)