CVE-2024-10860
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 28, 2025
Updated: Mar 6, 2025
CWE ID 862
Summary
CVE-2024-10860 is a vulnerability affecting the NextMove Lite – Thank You Page plugin for WordPress. The issue lies in the _submit_uninstall_reason_action() function, which lacks adequate capability checks. This oversight enables authenticated attackers with Subscriber-level access or higher to submit deactivation reasons on behalf of affected sites, resulting in unauthorized data submission.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.