ZeroHour

CVE-2026-81786

moderate

Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-81786 is a missing-authorization flaw (CWE-862) in the Thank You Page Customizer for WooCommerce WordPress plugin, allowing an unauthenticated attacker to invoke a restricted function without any login or user interaction. It is triggered by sending a crafted, unauthenticated HTTP request to the vulnerable routine on any site running an affected version. The CVSS 3.1 score of 7.5 (network vector, no privileges required) indicates the attacker gains high confidentiality impact, with no integrity or availability impact. Any WordPress/WooCommerce site running the plugin at version 1.2.2 or older is affected. No public proof-of-concept, no known in-the-wild exploitation, and the vulnerability is not listed in CISA KEV.

What to do: Update the plugin to the latest release (any version above 1.2.2) via the WordPress admin or the WordPress.org plugin directory. If an immediate update is not possible, deactivate the plugin until a patched version is available, since there is no public PoC or signature to detect attacks. Review access logs for unexpected unauthenticated requests to the site's AJAX/admin-post endpoints referencing this plugin.

Affected
VillaTheme Thank You Page Customizer for WooCommerce (WordPress plugin)<= 1.2.2
Estimated exposure
moderateroughly 10,000–20,000+ WordPress sites (WordPress.org active-install count for the plugin) — Estimated from the plugin's published WordPress.org active-install count (on the order of tens of thousands), of which only a subset run affected versions with WooCommerce active; exact exposure is an estimate and could be lower.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions.

Ecosystems
WordPress, E-commerce
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.