Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

XLPlugins — Vulnerabilities & Security Advisories 10

Browse all 10 CVE security advisories affecting XLPlugins. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2025-68048 WordPress NextMove Lite plugin <= 2.23.0 - Broken Access Control vulnerability — NextMove LiteCWE-862 8.1AIHighAI2026-02-20
CVE-2026-24599 WordPress NextMove Lite plugin <= 2.23.0 - Insecure Direct Object References (IDOR) vulnerability — NextMove LiteCWE-639 9.1 -2026-01-23
CVE-2025-62969 WordPress NextMove Lite plugin <= 2.23.0 - Cross Site Scripting (XSS) vulnerability — NextMove LiteCWE-79 5.4AIMediumAI2025-10-27
CVE-2025-52735 WordPress NextMove Lite plugin <= 2.24.0 - Cross Site Scripting (XSS) vulnerability — NextMove LiteCWE-79 7.1 High2025-10-22
CVE-2024-10860 NextMove Lite – Thank You Page for WooCommerce <= 2.19.0 - Missing Authorization to Authenticated (Subscriber+) Deactivation Reason Submission — NextMove Lite – Thank You Page for WooCommerceCWE-862 4.3 Medium2025-02-28
CVE-2024-30485 WordPress Finale Lite plugin <= 2.18.0 - Subscriber+ Arbitrary Plugin Installation/Activation vulnerability — Finale LiteCWE-862 8.8 High2024-06-09
CVE-2024-25092 WordPress NextMove Lite plugin <= 2.17.0 - Subscriber+ Arbitrary Plugin Installation/Activation vulnerability — NextMove LiteCWE-862 8.8 High2024-06-09
CVE-2024-32104 WordPress NextMove Lite plugin <= 2.18.1 - Cross Site Request Forgery (CSRF) vulnerability — NextMove LiteCWE-352 4.3 Medium2024-04-15
CVE-2024-32107 WordPress Finale Lite plugin <= 2.18.0 - Cross Site Request Forgery (CSRF) vulnerability — Finale LiteCWE-352 4.3 Medium2024-04-11
CVE-2023-39162 WordPress User Email Verification for WooCommerce Plugin <= 3.5.0 is vulnerable to Cross Site Scripting (XSS) — User Email Verification for WooCommerceCWE-79 7.1 High2023-09-04

This page lists every published CVE security advisory associated with XLPlugins. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.