Description
WordPress Plugin NextMove Lite-Thank You Page for WooCommerce is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently install and activate arbitrary plugins. WordPress Plugin NextMove Lite-Thank You Page for WooCommerce version 2.17.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.18.0 or latest
References
https://github.com/RandomRobbieBF/CVE-2024-25092
https://plugins.svn.wordpress.org/woo-thank-you-page-nextmove-lite/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Events Manager Cross-Site Scripting (5.8.1.3)
WordPress Plugin Csv2WPeC Coupon Arbitrary File Upload (1.1)
Oracle Database Server CVE-2018-3110 Vulnerability (CVE-2018-3110)
Apache version older than 1.3.29
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-4625)