CVE-2025-66528: Villatheme Thank You Page Customizer For Woocommerce
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Thank You Page Customizer for WooCommerce: from n/a through <= 1.1.8.
Affected products
- Villatheme Thank You Page Customizer For Woocommerce: up to and including 1.1.8
Published 2025-12-09. Last modified 2026-10-07.