CVE-2024-25092: WordPress NextMove Lite plugin <= 2.17.0 - Subscriber+ Arbitrary Plugin Installation/Activation vulnerability
Published Jun 9, 2024
·Updated
Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0.
Affected Software
1 affected component
XLPlugins Nextmove Wordpress<2.18.0
Remediation
Information
Update to 2.18.0 or a higher version.
Event History
Jun 9, 2024
CVE Published
via MITRE·10:28 AM
Data Sourced
via MITRE·10:28 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25092?
CVE-2024-25092 has a medium severity rating due to missing authorization controls.
2
How do I fix CVE-2024-25092?
To fix CVE-2024-25092, update the XLPlugins NextMove Lite plugin to version 2.18.0 or later.
3
What versions are affected by CVE-2024-25092?
CVE-2024-25092 affects versions of NextMove Lite from n/a through 2.17.0.
4
What impact does CVE-2024-25092 have on users?
CVE-2024-25092 allows unauthorized users to install and activate plugins, posing a security risk.
5
Is there a patch available for CVE-2024-25092?
Yes, a patch is available by updating NextMove Lite to at least version 2.18.0.