What the vulnerability does
01Description
The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of data due to a missing capability check on the _submit_uninstall_reason_action() function in all versions up to, and including, 2.19.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to submit a deactivation reason on behalf of a site.
Explanation of Vulnerability in Simple Terms
02Summary
The NextMove Lite plugin for WooCommerce does not properly check user permissions before allowing certain actions. A logged-in user with low privileges can modify data they should not have access to. The vulnerability affects all versions up to 2.19.0. Site owners should update to a version newer than 2.19.0 when available.
What an attacker can do
03Attacker Capabilities
A low-privilege user can modify data they should not have access to.
Potential impact on your site
04Site Impact
Unauthorized users may alter WooCommerce thank-you page settings or related data.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account on the site (e.g., customer or subscriber role).
Key dates
06Disclosure timeline
February 28, 2025
CVE published
April 8, 2026
Record updated