What the vulnerability does
01Description
Missing Authorization vulnerability in WooCommerce & WordPress Tutorials Custom Thank You Page Customize For WooCommerce by Binary Carpenter.This issue affects Custom Thank You Page Customize For WooCommerce by Binary Carpenter: from n/a through 1.4.12.
Explanation of Vulnerability in Simple Terms
02Summary
The Custom Thank You Page Customize For WooCommerce plugin for WordPress does not properly check user permissions before allowing modifications to thank-you page settings. A logged-in user with low privileges can change these settings without authorization. This affects versions up to 1.4.12. Update the plugin to a version newer than 1.4.12.
What an attacker can do
03Attacker Capabilities
A low-privilege user can modify WooCommerce thank-you page settings without proper authorization.
Potential impact on your site
04Site Impact
Unauthorized users can alter thank-you page content, potentially redirecting customers or displaying misleading information.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
April 17, 2024
CVE published
April 28, 2026
Record updated