CVE-2026-81786
moderateUnauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce
CVE-2026-81786 is a missing-authorization flaw (CWE-862) in the Thank You Page Customizer for WooCommerce WordPress plugin, allowing an unauthenticated attacker to invoke a restricted function without any login or user interaction. It is triggered by sending a crafted, unauthenticated HTTP request to the vulnerable routine on any site running an affected version. The CVSS 3.1 score of 7.5 (network vector, no privileges required) indicates the attacker gains high confidentiality impact, with no integrity or availability impact. Any WordPress/WooCommerce site running the plugin at version 1.2.2 or older is affected. No public proof-of-concept, no known in-the-wild exploitation, and the vulnerability is not listed in CISA KEV.
What to do: Update the plugin to the latest release (any version above 1.2.2) via the WordPress admin or the WordPress.org plugin directory. If an immediate update is not possible, deactivate the plugin until a patched version is available, since there is no public PoC or signature to detect attacks. Review access logs for unexpected unauthenticated requests to the site's AJAX/admin-post endpoints referencing this plugin.
| VillaTheme Thank You Page Customizer for WooCommerce (WordPress plugin) | <= 1.2.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions.
- Ecosystems
- WordPress, E-commerce
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.