Junglewise Threat Intelligence

CVE-2026-81786: Thank You Page Customizer for WooCommerce broken access control

CVE-2026-81786 · Severity: high · CVSS 7.5 · Published 2026-09-10

Vendors: VillaTheme.

Executive brief

Thank You Page Customizer for WooCommerce is a WordPress plugin that allows store administrators to customize order confirmation pages displayed to customers. An unauthenticated attacker can bypass access controls to view or modify pages they should not have permission to access, potentially exposing sensitive order data or tampering with customer-facing content across all WooCommerce stores using this plugin.

Technical details

This vulnerability is a broken access control flaw in the Thank You Page Customizer for WooCommerce plugin affecting versions up to 1.2.2. The plugin fails to properly validate user permissions when handling page access or modification requests, allowing unauthenticated attackers to bypass authorization checks over the network. An attacker can access administrative or customer-specific pages and potentially read or alter their contents without any credentials or special preconditions. The vulnerability was patched in version 1.2.3; users should update immediately.

Affected products

  • VillaTheme Thank You Page Customizer for WooCommerce <= 1.2.2

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Patched in version 1.2.3

References