PT-2026-97786 · WordPress · Custom Thank You Page For Woocommerce

·

CVE-2026-4806

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Custom Thank You Page for WooCommerce versions prior to 1.1.3
Description The plugin is subject to unauthorized access and data loss because the save option() function lacks a capability check. This flaw allows unauthenticated attackers to export or reset the plugin settings.
Recommendations Update the plugin to a version later than 1.1.2. As a temporary workaround, restrict access to the save option() function until the update is applied.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4806

Affected Products

Custom Thank You Page For Woocommerce