CVE-2024-10860

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 28, 2025
Updated: Mar 6, 2025
CWE ID 862

Summary

CVE-2024-10860 is a vulnerability affecting the NextMove Lite – Thank You Page plugin for WordPress. The issue lies in the _submit_uninstall_reason_action() function, which lacks adequate capability checks. This oversight enables authenticated attackers with Subscriber-level access or higher to submit deactivation reasons on behalf of affected sites, resulting in unauthorized data submission.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share