Unauthorized Data Access in Custom Thank You Page for WooCommerce Plugin by WordPress
CVE-2026-4806
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 September 2026
What is CVE-2026-4806?
The Custom Thank You Page for WooCommerce plugin for WordPress suffers from an unauthorized access vulnerability due to a missing capability check in the save_option() function. This flaw affects all versions up to and including 1.1.2, allowing unauthenticated attackers the potential to export or reset (delete) the plugin's settings, which could lead to data loss and misconfiguration. Users are advised to update to secure versions promptly.
Affected Version(s)
Custom Thank You Page for WooCommerce 0 <= 1.1.2