VYPR
Medium severity4.3NVD Advisory· Published Dec 9, 2025· Updated Apr 27, 2026

CVE-2025-66528

CVE-2025-66528

Description

Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Thank You Page Customizer for WooCommerce: from n/a through <= 1.1.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Thank You Page Customizer for WooCommerce plugin <=1.1.8 has a broken access control vulnerability allowing unauthenticated attackers to access unauthorized functionality.

Vulnerability

Overview The Thank You Page Customizer for WooCommerce plugin (versions up to and including 1.1.8) suffers from a missing authorization vulnerability. This broken access control issue arises from insufficient validation of user permissions or missing nonce tokens in certain functions, leading to incorrect access control security levels [1].

Exploitation

Details Attackers can exploit this vulnerability without requiring any authentication. By sending specially crafted requests, they can bypass intended access restrictions and perform actions that should be reserved for higher-privileged users. The attack surface is broad, as the vulnerability affects all websites running the affected plugin versions [1].

Impact

Successful exploitation could allow an unauthenticated attacker to access sensitive data or execute unauthorized operations within the WooCommerce environment. This may lead to data exposure, order manipulation, or other malicious activities, depending on the missing checks [1].

Mitigation

The vulnerability is addressed in version 1.1.9 of the plugin. Users are strongly advised to update to this version or later immediately. For Patchstack users, enabling auto-updates for vulnerable plugins can help prevent exploitation [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.