CVE-2025-52735: WordPress NextMove Lite plugin <= 2.24.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Reflected XSS.This issue affects NextMove Lite: from n/a through <= 2.24.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52735?
CVE-2025-52735 has been classified as a medium severity vulnerability due to its potential for exploitation via reflected cross-site scripting.
How do I fix CVE-2025-52735?
To fix CVE-2025-52735, update the NextMove Lite plugin to the latest version beyond 2.21.0.
What is the impact of CVE-2025-52735?
CVE-2025-52735 allows an attacker to execute arbitrary JavaScript in the context of a user’s browser, leading to potential data theft or session hijacking.
Which versions are affected by CVE-2025-52735?
CVE-2025-52735 affects XLPlugins NextMove Lite versions up to and including 2.21.0.
Are there any workarounds for CVE-2025-52735?
As a workaround for CVE-2025-52735, consider disabling the plugin until it can be updated to a patched version.