CVE-2026-103071: Villatheme Thank You Page Customizer For Woocommerce

High severity, CVSS 7.5.

Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from n/a through 1.2.3.

Affected products

  • Villatheme Thank You Page Customizer For Woocommerce: up to and including 1.2.3

Published 2026-10-10. Last modified 2026-10-10.