CVE-2025-30993: WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.1.7 - Broken Access Control Vulnerability
Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce – Increase Your Sales allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Thank You Page Customizer for WooCommerce – Increase Your Sales: from n/a through 1.1.7.
Other sources
Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Thank You Page Customizer for WooCommerce: from n/a through <= 1.1.7.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30993?
CVE-2025-30993 has been rated as a high severity vulnerability due to the potential for unauthorized access and data exposure.
How do I fix CVE-2025-30993?
To fix CVE-2025-30993, update the VillaTheme Thank You Page Customizer for WooCommerce – Increase Your Sales plugin to version 1.1.8 or later, which addresses the missing authorization issue.
What causes the CVE-2025-30993 vulnerability?
CVE-2025-30993 is caused by incorrectly configured access control security levels in the plugin, leading to a lack of authorization checks.
Who is affected by CVE-2025-30993?
Users of the VillaTheme and WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales plugin versions up to 1.1.7 are affected by CVE-2025-30993.
What are the potential impacts of exploiting CVE-2025-30993?
Exploiting CVE-2025-30993 could allow unauthorized users to access sensitive information and modify the thank-you page configuration.