PT-2025-43227 · Xlplugins · Nextmove Lite+1

Lvt-Tholv2K

·

Published

2025-10-22

·

Updated

2025-11-18

·

CVE-2025-52735

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions XLPlugins NextMove Lite versions through 2.21.0
Description The software contains a flaw related to improper input handling during web page generation, which allows for Reflected Cross-site Scripting (XSS). This issue is present in the 'woo-thank-you-page-nextmove-lite' component. The vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users. The affected component is susceptible to exploitation through crafted input.
Recommendations Update XLPlugins NextMove Lite to a version newer than 2.21.0.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-52735

Affected Products

Nextmove Lite
Nextmove