Stored Cross-Site Scripting Vulnerability in NextMove Lite - Thank You Page for WooCommerce Plugin
CVE-2026-0703

6.4MEDIUM

What is CVE-2026-0703?

The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress has a vulnerability that allows for stored cross-site scripting (XSS) attacks. This issue arises from inadequate input sanitization and failure to escape output on user-provided attributes, particularly through the 'xlwcty_current_date' shortcode. As a result, authenticated attackers with contributor-level access can inject malicious web scripts that execute whenever users visit the compromised pages, posing significant security threats to platforms utilizing this plugin. Timely updates and security measures are essential to mitigate potential exploits.

Affected Version(s)

NextMove Lite – Thank You Page for WooCommerce 0 <= 2.23.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ
.