Authorization Flaw in VillaTheme Thank You Page Customizer for WooCommerce
CVE-2025-66528
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-66528?
A missing authorization vulnerability exists in the VillaTheme Thank You Page Customizer for WooCommerce. This issue stems from incorrectly configured access control security levels, which may allow unauthorized users to exploit the settings of the plugin. Affected users are encouraged to update their installations to secure their e-commerce operations against potential threats.
Affected Version(s)
Thank You Page Customizer for WooCommerce 0 <= 1.1.8