What the vulnerability does
01Description
Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0.
Explanation of Vulnerability in Simple Terms
NextMove Lite through version 2.17.0 fails to properly check user permissions before allowing access to sensitive functions. A logged-in user with low privileges can read, modify, or delete data they should not have access to, or perform administrative actions without authorization. The vulnerability affects all users of the plugin.
What an attacker can do
A low-privilege logged-in user can read, modify, or delete data and perform admin actions without authorization.
Potential impact on your site
Unauthorized users can access, modify, or delete sensitive site data and perform administrative functions.
Conditions required to exploit
Attacker must have a low-privilege account on the site (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities