CVE-2025-68048: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68048 is a Missing Authorization vulnerability in the XLPlugins NextMove Lite WordPress plugin (slug: woo-thank-you-page-nextmove-lite) that allows unauthenticated remote attackers to exploit incorrectly configured access control security levels. It affects all versions of NextMove Lite through 2.23.0. The vulnerability was published on February 20, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Feedly, Wordfence).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before granting access to sensitive functionality or data. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The vulnerability stems from incorrectly configured access control on one or more plugin endpoints, allowing unauthorized access to protected resources (Feedly).

Impact

Successful exploitation results in a high confidentiality impact with no integrity or availability impact, meaning attackers can access sensitive information exposed by the plugin without being able to modify data or disrupt service. Given that NextMove Lite is a WooCommerce thank-you page plugin, exposed data could include order details, customer personally identifiable information (PII), or other transactional data accessible through unprotected endpoints. The scope is limited to the affected WordPress installation, but data exposure could affect all customers whose order information is processed by the plugin (Feedly).

Exploitability

There is no public evidence of active in-the-wild exploitation or weaponized exploit code at this time. The EPSS score is approximately 0.017% (0.000170), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the NextMove Lite plugin (version ≤ 2.23.0) using tools like WPScan, Shodan, or by checking publicly accessible readme.txt files at /wp-content/plugins/woo-thank-you-page-nextmove-lite/readme.txt.
  2. Identify unprotected endpoints: Enumerate plugin-registered REST API routes or admin-ajax actions associated with NextMove Lite that lack proper capability checks.
  3. Send unauthenticated request: Craft an HTTP GET or POST request to the identified endpoint without any authentication credentials or nonce tokens.
  4. Extract sensitive data: Review the server response for exposed order details, customer PII, or other sensitive WooCommerce data returned due to the missing authorization check (Feedly).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP requests to WordPress REST API endpoints or wp-admin/admin-ajax.php actions associated with the NextMove Lite plugin (woo-thank-you-page-nextmove-lite).
  • Logs: WordPress access logs showing repeated requests to plugin-specific endpoints from unknown or automated IP addresses without session cookies or authentication headers.
  • Logs: High volume of requests to thank-you page or order-related plugin endpoints from a single IP or user agent string indicative of automated scanning.

Mitigation and workarounds

Users should update the NextMove Lite plugin to a version beyond 2.23.0 as soon as a patched release is made available by XLPlugins. In the interim, site administrators can consider disabling the plugin if it is not critical to operations, or restricting access to WordPress plugin endpoints via web application firewall (WAF) rules. Monitoring plugin update channels and the WordPress plugin repository for a patched release is strongly recommended (Feedly, Wordfence).

Community reactions

Wordfence included this vulnerability in their weekly WordPress vulnerability report covering January 26 – February 1, 2026, highlighting it as part of a broader set of access control issues affecting WordPress plugins (Wordfence). No significant additional vendor statements or notable researcher commentary beyond standard disclosure reporting have been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management