Description
WordPress Plugin NextMove Lite-Thank You Page for WooCommerce is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently install and activate arbitrary plugins. WordPress Plugin NextMove Lite-Thank You Page for WooCommerce version 2.17.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.18.0 or latest
References
https://github.com/RandomRobbieBF/CVE-2024-25092
https://plugins.svn.wordpress.org/woo-thank-you-page-nextmove-lite/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Direct Download for Woocommerce Arbitrary File Download (1.15)
Django Inefficient Algorithmic Complexity Vulnerability (CVE-2026-33033)
WordPress Plugin Nextend Facebook Connect Unspecified Vulnerability (1.5.7)
Dolibarr Improper Handling of Case Sensitivity Vulnerability (CVE-2026-89012)
Ruby on Rails 7PK - Security Features Vulnerability (CVE-2015-7576)