What the vulnerability does
01Description
The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing authorization e in all versions up to, and including, 1.1.2 via the apply_layout function due to a missing capability check. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve arbitrary order data which may contain PII.
Explanation of Vulnerability in Simple Terms
02Summary
The Thank You Page Customizer for WooCommerce plugin through version 1.1.2 does not properly check user permissions before allowing access to certain administrative functions. A logged-in user with low privileges can view sensitive configuration data that should be restricted to site administrators. The vulnerability requires an active user account but no special interaction.
What an attacker can do
03Attacker Capabilities
Read sensitive plugin configuration and settings intended only for administrators.
Potential impact on your site
04Site Impact
Customer or subscriber accounts can access admin-level plugin settings and potentially sensitive WooCommerce configuration data.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account (e.g., subscriber or customer) on the WordPress site.
Key dates
06Disclosure timeline
February 27, 2024
CVE published
April 8, 2026
Record updated