Stored Cross-Site Scripting Vulnerability in NextMove Lite - Thank You Page for WooCommerce Plugin
CVE-2026-0703
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 May 2026
What is CVE-2026-0703?
The NextMove Lite β Thank You Page for WooCommerce plugin for WordPress has a vulnerability that allows for stored cross-site scripting (XSS) attacks. This issue arises from inadequate input sanitization and failure to escape output on user-provided attributes, particularly through the 'xlwcty_current_date' shortcode. As a result, authenticated attackers with contributor-level access can inject malicious web scripts that execute whenever users visit the compromised pages, posing significant security threats to platforms utilizing this plugin. Timely updates and security measures are essential to mitigate potential exploits.
Affected Version(s)
NextMove Lite β Thank You Page for WooCommerce 0 <= 2.23.0