
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68048 is a Missing Authorization vulnerability in the XLPlugins NextMove Lite WordPress plugin (slug: woo-thank-you-page-nextmove-lite) that allows unauthenticated remote attackers to exploit incorrectly configured access control security levels. It affects all versions of NextMove Lite through 2.23.0. The vulnerability was published on February 20, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Feedly, Wordfence).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before granting access to sensitive functionality or data. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The vulnerability stems from incorrectly configured access control on one or more plugin endpoints, allowing unauthorized access to protected resources (Feedly).
Successful exploitation results in a high confidentiality impact with no integrity or availability impact, meaning attackers can access sensitive information exposed by the plugin without being able to modify data or disrupt service. Given that NextMove Lite is a WooCommerce thank-you page plugin, exposed data could include order details, customer personally identifiable information (PII), or other transactional data accessible through unprotected endpoints. The scope is limited to the affected WordPress installation, but data exposure could affect all customers whose order information is processed by the plugin (Feedly).
There is no public evidence of active in-the-wild exploitation or weaponized exploit code at this time. The EPSS score is approximately 0.017% (0.000170), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).
readme.txt files at /wp-content/plugins/woo-thank-you-page-nextmove-lite/readme.txt.wp-admin/admin-ajax.php actions associated with the NextMove Lite plugin (woo-thank-you-page-nextmove-lite).Users should update the NextMove Lite plugin to a version beyond 2.23.0 as soon as a patched release is made available by XLPlugins. In the interim, site administrators can consider disabling the plugin if it is not critical to operations, or restricting access to WordPress plugin endpoints via web application firewall (WAF) rules. Monitoring plugin update channels and the WordPress plugin repository for a patched release is strongly recommended (Feedly, Wordfence).
Wordfence included this vulnerability in their weekly WordPress vulnerability report covering January 26 – February 1, 2026, highlighting it as part of a broader set of access control issues affecting WordPress plugins (Wordfence). No significant additional vendor statements or notable researcher commentary beyond standard disclosure reporting have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."