Extension WordPress
Vulnérabilités NextMove Lite – Thank You Page for WooCommerce
Cette page rassemble les failles publiées pour NextMove Lite – Thank You Page for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de NextMove Lite – Thank You Page for WooCommerce
9 fiches
NextMove Lite – Thank You Page for WooCommerce <= 2.23.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'xlwcty_current_date' Shortcode
The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xlwcty_current_date' shortcode in all versions up to, and including, 2.23.0 due to insufficient input sanitization and output…
*-2.23.0
2.24.0
01/05/2026
NextMove Lite <= 2.23.0 – Missing Authorization
The NextMove Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.23.0. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-2.23.0
2.24.0
27/01/2026
NextMove Lite <= 2.23.0 – Unauthenticated Insecure Direct Object Reference
The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.23.0 due to missing validation on a user controlled key. This makes…
*-2.23.0
2.24.0
15/01/2026
NextMove Lite <= 2.23.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The NextMove Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.23.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-2.23.0
2.24.0
18/10/2025
NextMove Lite <= 2.21.0 – Reflected Cross-Site Scripting
The NextMove Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.21.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-2.21.0
Non indiqué
28/07/2025
NextMove Lite – Thank You Page for WooCommerce <= 2.19.0 – Missing Authorization to Authenticated (Subscriber+) Deactivation Reason Submission
The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of data due to a missing capability check on the _submit_uninstall_reason_action() function in all versions up to, and including, 2.19.0. This…
*-2.19.0
2.20.0
27/02/2025
NextMove Lite <= 2.18.1 – Cross-Site Request Forgery
The NextMove Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.1. This is due to missing or incorrect nonce validation on the xl_addon_installation() function. This makes it possible for unauthenticated…
*-2.18.1
2.18.2
11/04/2024
NextMove Lite – Thank You Page for WooCommerce & Finale Lite – Sales Countdown Timer & Discount for WooCommerce <= 2.17.0 – Missing Authorization to Unauthenticated System Information Disclosure
The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the…
*-2.18.0
2.18.1
29/02/2024
NextMove Lite <= 2.17.0 – Missing Authorization to Authenticated(Subscriber+) Plugin Activation
The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'xl_addon_installation' function in all versions up to, and including, 2.17.0. This…
*-2.17.0
2.18.0
09/02/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.