The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to export or reset(delete) the plugin's settings.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 24 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to export or reset(delete) the plugin's settings. | |
| Title | Custom Thank You Page for WooCommerce <= 1.1.2 - Missing Authorization to Unauthenticated Settings Export and Settings Reset | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-09-24T15:14:17.534Z
Reserved: 2026-03-25T12:20:08.456Z
Link: CVE-2026-4806
No data.
Status : Deferred
Published: 2026-09-24T12:17:12.307
Modified: 2026-09-24T16:17:07.523
Link: CVE-2026-4806
No data.
OpenCVE Enrichment
Updated: 2026-09-24T12:30:18Z
Weaknesses