CVE-2025-66528
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-66528 is a Missing Authorization (Broken Access Control) vulnerability in VillaTheme's Thank You Page Customizer for WooCommerce WordPress plugin. It affects all versions up to and including 1.1.8, and was reported by researcher "daroo" on November 5, 2025, with public disclosure on December 5–9, 2025. The vulnerability was assigned by Patchstack and carries a CVSS v3.1 base score of 8.1 (High) per NVD, while Patchstack rates it 4.3 (Medium) using their WordPress-specific scoring methodology (Patchstack, Feedly).

Technical details

The root cause is CWE-862 (Missing Authorization), where one or more plugin functions lack proper authorization, authentication, or nonce token checks before executing privileged actions (OWASP A1: Broken Access Control). An authenticated attacker with low privileges (e.g., a Subscriber-level WordPress account) can invoke these insufficiently protected functions over the network without user interaction, bypassing intended access control restrictions. No complex preconditions are required beyond having a valid low-privilege account on the target WordPress site. No public technical write-up or proof-of-concept code detailing the specific vulnerable function has been published (Patchstack).

Impact

Successful exploitation allows a low-privilege authenticated attacker to gain unauthorized access to sensitive information (high confidentiality impact) and modify or corrupt protected plugin resources (high integrity impact). Availability is not directly affected. In a WooCommerce context, this could expose order-related data or allow unauthorized customization of post-purchase pages, potentially enabling data harvesting or manipulation of customer-facing content (Feedly, Patchstack).

Mitigation and workarounds

The vulnerability is patched in version 1.1.9 of the Thank You Page Customizer for WooCommerce plugin. Site administrators should update to version 1.1.9 or later immediately via the WordPress plugin dashboard. If an immediate update is not possible, consider temporarily deactivating the plugin or restricting site registration to prevent low-privilege account creation. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13147CRITICAL9.1
  • kirki
NoYesJul 20, 2026
CVE-2026-9833HIGH7.1
  • tag-groups
NoYesJul 20, 2026
CVE-2026-13432MEDIUM5.4
  • image-sizes
NoYesJul 20, 2026
CVE-2026-13156MEDIUM5.4
  • mailersend-official-smtp-integration
NoYesJul 20, 2026
CVE-2026-8825MEDIUM4.9
  • elementor
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management