
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66528 is a Missing Authorization (Broken Access Control) vulnerability in VillaTheme's Thank You Page Customizer for WooCommerce WordPress plugin. It affects all versions up to and including 1.1.8, and was reported by researcher "daroo" on November 5, 2025, with public disclosure on December 5–9, 2025. The vulnerability was assigned by Patchstack and carries a CVSS v3.1 base score of 8.1 (High) per NVD, while Patchstack rates it 4.3 (Medium) using their WordPress-specific scoring methodology (Patchstack, Feedly).
The root cause is CWE-862 (Missing Authorization), where one or more plugin functions lack proper authorization, authentication, or nonce token checks before executing privileged actions (OWASP A1: Broken Access Control). An authenticated attacker with low privileges (e.g., a Subscriber-level WordPress account) can invoke these insufficiently protected functions over the network without user interaction, bypassing intended access control restrictions. No complex preconditions are required beyond having a valid low-privilege account on the target WordPress site. No public technical write-up or proof-of-concept code detailing the specific vulnerable function has been published (Patchstack).
Successful exploitation allows a low-privilege authenticated attacker to gain unauthorized access to sensitive information (high confidentiality impact) and modify or corrupt protected plugin resources (high integrity impact). Availability is not directly affected. In a WooCommerce context, this could expose order-related data or allow unauthorized customization of post-purchase pages, potentially enabling data harvesting or manipulation of customer-facing content (Feedly, Patchstack).
The vulnerability is patched in version 1.1.9 of the Thank You Page Customizer for WooCommerce plugin. Site administrators should update to version 1.1.9 or later immediately via the WordPress plugin dashboard. If an immediate update is not possible, consider temporarily deactivating the plugin or restricting site registration to prevent low-privilege account creation. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."