NextMove Lite WooCommerce Plugin Missing Authorization Vulnerability for Deactivation Reason Submission

Vulnerability

A vulnerability exists in the NextMove Lite - Thank You Page for WooCommerce plugin for WordPress, in versions through 2.19.0. The issue arises from a lack of proper capability checks in the '_submit_uninstall_reason_action()' function. This flaw allows authenticated attackers with Subscriber-level access and above to submit deactivation reasons on behalf of a site, potentially leading to unauthorized changes in plugin management or user experience.

Impact

Exploitation of this vulnerability allows for unauthorized submission of deactivation reasons, which could be used to manipulate plugin behavior or user notifications.

Reproduction

To reproduce this vulnerability, an authenticated user with Subscriber-level access or higher can send a request to the WordPress site that includes a deactivation reason. This can be done through the WordPress admin interface, where the NextMove Lite WooCommerce plugin is managed. The absence of a required capability check allows the submission to be processed, even though the user may not have the appropriate permissions to make such a change.

Remediation

Users are advised to update the NextMove Lite - Thank You Page for WooCommerce plugin to version 2.20.0 or later, where this vulnerability has been patched.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.3
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.