PT-2026-4433 · Xlplugins · Woo-Thank-You-Page-Nextmove-Lite+1

Ppzzaarr

·

Published

2026-01-23

·

Updated

2026-01-24

·

CVE-2026-24599

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions XLPlugins NextMove Lite versions through 2.23.0
Description An authorization bypass exists due to incorrectly configured access control security levels. This allows exploitation through a user-controlled key. The issue is present in the woo-thank-you-page-nextmove-lite component.
Recommendations Update XLPlugins NextMove Lite to a version newer than 2.23.0.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-24599

Affected Products

Nextmove Lite
Woo-Thank-You-Page-Nextmove-Lite