All 6 CVE vulnerabilities found in NextMove Lite, with AI-generated Chinese analysis, references, and POCs.
Vendor: XLPlugins
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-68048 | WordPress NextMove Lite plugin <= 2.23.0 - Broken Access Control vulnerability CWE-862 | 7.5 | High | 2026-02-20 |
| CVE-2026-24599 | WordPress NextMove Lite plugin <= 2.23.0 - Insecure Direct Object References (IDOR) vulnerability CWE-639 | 5.3 | Medium | 2026-01-23 |
| CVE-2025-62969 | WordPress NextMove Lite plugin <= 2.23.0 - Cross Site Scripting (XSS) vulnerability CWE-79 | 6.5 | Medium | 2025-10-27 |
| CVE-2025-52735 | WordPress NextMove Lite plugin <= 2.24.0 - Cross Site Scripting (XSS) vulnerability CWE-79 | 7.1 | High | 2025-10-22 |
| CVE-2024-25092 | WordPress NextMove Lite plugin <= 2.17.0 - Subscriber+ Arbitrary Plugin Installation/Activation vulnerability CWE-862 | 8.8 | High | 2024-06-09 |
| CVE-2024-32104 | WordPress NextMove Lite plugin <= 2.18.1 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 | 4.3 | Medium | 2024-04-15 |
All 6 known CVE vulnerabilities affecting NextMove Lite with full Chinese analysis, references, and POCs where available.