Access violation vulnerability in Thank You Page Customizer for WooCommerce – Increase Your Sales 1.1.2

The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress has a security vulnerability that allows unauthorized users to run shortcodes. This is because the get_text_editor_content() function is missing a check for user permissions in all versions up to 1.1.2. This means that anyone with subscriber or higher level access can potentially run any type of shortcode on the website.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.