Unauthorized Access to System Information in NextMove Lite and Finale Lite Plugins
CVE-2024-1120
Key Information:
- Vendor
Wordpress
- Status
- Vendor
- CVE Published:
- 1 March 2024
What is CVE-2024-1120?
The NextMove Lite β Thank You Page for WooCommerce and Finale Lite β Sales Countdown Timer & Discount for WooCommerce plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the download_tools_settings() function in all versions up to, and including, 2.17.0. This makes it possible for unauthenticated attackers to export system information that can aid attackers in an attack.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Finale Lite β Sales Countdown Timer & Discount for WooCommerce * <= 2.17.0
NextMove Lite β Thank You Page for WooCommerce * <= 2.18.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved