f
finale
Security Risk Profile
22
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 2 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 1, 2024 to present
2
Total CVEs
0
Critical+High
0
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
4.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
22/100
low
🆕 1Fresh (<7d)📈 1 in Last 30 Days
Severity Distribution
Critical
0High
0Medium
2Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
Infoleak
1
Most Affected Products
1. Finale Finale Lite (WordPress plugin)1
2. NextMove Lite – Thank You Page for WooCommerce1
3. Finale Lite – Sales Countdown Timer & Discount for WooCommerce1
4. XLPlugins Finale Wordpress1
5. XLPlugins Nextmove Wordpress1
Recent Vulnerabilities
See more →CVE-2026-78138
CVSS 4.3medium
Finale Lite < 2.21.0 - Subscriber+ Campaign Configuration Disclosure via wcct_quick_view_html
Aug 27, 2026🔧 No Patch
CVE-2024-1120
CVSS 5.3medium
NextMove Lite – Thank You Page for WooCommerce & Finale Lite – Sales Countdown Timer & Discount for WooCommerce <= 2.17.0 - Missing Authorization to Unauthenticated System Information Disclosure
Mar 1, 2024
Monitor finale in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.