Sceawere
Vulnerability Detail
CVE-2026-103071UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Code Injection in Thank You Page Customizer
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- VillaTheme
- Product
- Thank You Page Customizer for WooCommerce
- Attack Type
- Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from n/a through 1.2.3.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-10T17:16:59.673Z",
"pubdate": "2026-10-10T17:16:59.673Z",
"executiveSummary": "The VillaTheme Thank You Page Customizer for WooCommerce plugin is susceptible to a Code Injection vulnerability, categorized under CWE-94: Improper Control of Generation of Code.\nThis security flaw allows an authenticated attacker to inject and execute arbitrary code, potentially leading to unauthorized system command execution or unauthorized data access.\nThe vulnerability affects all versions of the Thank You Page Customizer for WooCommerce from n/a through 1.2.3.\nThe risk is significant as successful exploitation could lead to full site compromise, sensitive data exfiltration, or the deployment of malicious backdoors on the underlying server.\nAttackers require authenticated access to the plugin's configuration interfaces to leverage the injection vectors. Once accessed, the lack of proper input validation allows the attacker to supply malicious scripts or server-side code that is processed and executed by the web server within the context of the WordPress application.",
"technicalDetails": "The vulnerability exists due to insufficient sanitization and validation of user-supplied input within the Thank You Page Customizer for WooCommerce plugin. Specifically, the plugin fails to properly restrict or sanitize data passed to internal functions responsible for generating or rendering custom page content.\nThe root cause is the improper handling of dynamic inputs, which allows an attacker to inject executable code snippets. When the plugin processes these inputs, it fails to enforce strict type checking or character filtering, enabling the persistence or immediate execution of malicious code.\nThe attack flow begins with the attacker accessing the plugin's administrative settings or customization interfaces. By manipulating parameters associated with custom thank-you page content, the attacker can insert malicious code—typically PHP or script-based payloads—into the database fields.\nUpon saving the configuration, the application stores this injected payload. When a user or administrator subsequently accesses the affected WooCommerce thank-you page, the application retrieves the malicious input and executes it as part of the page generation process. Because this execution occurs on the server side or via the client browser depending on the specific injection point, it can lead to Remote Code Execution (RCE) or Cross-Site Scripting (XSS) depending on how the application handles the stored input.\nAffected versions are identified as n/a through 1.2.3. The vulnerability requires authenticated access, typically by a user with sufficient privileges to modify plugin settings, such as an administrator or a user with specific shop management capabilities.\nPost-exploitation impact includes the potential for total server compromise. If the injected code runs with the privileges of the web server user, the attacker can perform arbitrary actions, including reading or modifying database contents, exfiltrating configuration files (like wp-config.php), or initiating lateral movement within the hosting environment.\nThe lack of server-side input filtering prevents the plugin from rejecting or neutralizing malicious characters or syntax, making the application's template engine a direct vector for code execution."
}