CVE-2025-62969: WordPress NextMove Lite plugin <= 2.23.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Stored XSS.This issue affects NextMove Lite: from n/a through <= 2.23.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62969?
CVE-2025-62969 is classified as a moderate severity vulnerability due to its risk of allowing stored cross-site scripting (XSS).
How do I fix CVE-2025-62969?
To fix CVE-2025-62969, update the XLPlugins NextMove Lite plugin to version 2.21.1 or later.
Which versions are affected by CVE-2025-62969?
CVE-2025-62969 affects all versions of XLPlugins NextMove Lite up to and including 2.21.0.
What is the impact of CVE-2025-62969?
CVE-2025-62969 allows attackers to execute arbitrary JavaScript in the context of the user's session, potentially compromising user data.
Is CVE-2025-62969 specific to any platform?
CVE-2025-62969 is specific to the XLPlugins NextMove Lite plugin used in WordPress.