Skip to main content

CVE-2026-4806: WooCommerce Thank You Page Auth Bypass Flaw

CVE-2026-4806 is an authentication bypass flaw in the Custom Thank You Page for WooCommerce plugin that lets unauthenticated attackers export or delete plugin settings. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-4806 Overview

CVE-2026-4806 affects the Custom Thank You Page for WooCommerce plugin for WordPress. The plugin fails to perform a capability check on its save_option() function in all versions up to and including 1.1.2. Unauthenticated attackers can send crafted requests to export or reset the plugin's settings. The weakness is classified as Missing Authorization [CWE-862] and is exploitable remotely over the network without user interaction.

Critical Impact

Unauthenticated remote attackers can read or delete plugin configuration data on any WordPress site running the vulnerable plugin.

Affected Products

  • Custom Thank You Page for WooCommerce plugin for WordPress
  • All versions up to and including 1.1.2
  • WordPress sites with WooCommerce running the affected plugin

Discovery Timeline

  • 2026-09-24 - CVE-2026-4806 published to NVD
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-4806

Vulnerability Analysis

The vulnerability resides in the save_option() function exposed by the plugin. The function processes requests to export or reset plugin settings but does not verify the caller's privileges. Any unauthenticated visitor can invoke the endpoint and trigger administrative behavior.

Successful exploitation produces two outcomes. Attackers can export the plugin's configuration, disclosing settings that may contain sensitive storefront logic. Attackers can also reset the configuration, which deletes the stored options and disrupts the custom thank you page flow for WooCommerce transactions.

The weakness does not grant code execution or full site takeover. It does, however, enable information disclosure and integrity loss against WooCommerce storefronts that depend on this plugin for post-purchase redirects.

Root Cause

The root cause is a missing capability check [CWE-862] inside save_option(). The function should validate the current user against a WordPress capability such as manage_options and verify a nonce before processing export or reset actions. Neither check is present in versions up to 1.1.2.

Attack Vector

An attacker sends an HTTP request to the plugin's AJAX or admin-post handler that routes to save_option(). No session, token, or user interaction is required. The request parameters select either the export action or the reset action, and the server executes the operation without authorization validation.

The vulnerability mechanism is documented in the Wordfence Vulnerability Report and the corresponding fix is visible in the WordPress Plugins Change Log.

Detection Methods for CVE-2026-4806

Indicators of Compromise

  • Unauthenticated POST requests to admin-ajax.php or admin-post.php referencing the plugin's save_option action.
  • Unexpected resets of Custom Thank You Page for WooCommerce settings, including missing redirect URLs or restored defaults.
  • Outbound export responses containing plugin option data sent to non-administrative IP addresses.

Detection Strategies

  • Review web server access logs for requests to the plugin's action endpoints originating from unauthenticated sessions.
  • Correlate WordPress options table changes with the absence of a logged-in administrator session at the same timestamp.
  • Alert on repeated 200-status requests to save_option handlers from a single source IP.

Monitoring Recommendations

  • Enable WordPress audit logging for changes to plugin options and administrative settings.
  • Monitor WooCommerce order flow for broken post-checkout redirects that indicate a settings reset.
  • Forward WordPress and web server logs to a centralized analytics platform to retain evidence of unauthenticated administrative calls.

How to Mitigate CVE-2026-4806

Immediate Actions Required

  • Update the Custom Thank You Page for WooCommerce plugin to a version later than 1.1.2 as published in the plugin changeset 3507079.
  • Back up current plugin settings before patching so configuration can be restored if a reset occurred.
  • Restrict access to admin-ajax.php and admin-post.php from untrusted networks where feasible.

Patch Information

The vendor committed a fix in WordPress plugin changeset 3507079, which adds the missing capability check to save_option(). Site owners should install the patched release through the WordPress plugin updater. Additional advisory details are available in the Wordfence Vulnerability Report.

Workarounds

  • Deactivate the Custom Thank You Page for WooCommerce plugin until the update is applied.
  • Deploy a web application firewall rule that blocks unauthenticated requests to the plugin's save_option action parameter.
  • Audit WordPress option values after exposure and restore known-good settings from backup if a reset is detected.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.