CVE-2024-25092

HIGH

XLPlugins NextMove Lite <2.17.0 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2024-25092. PoCs published by RandomRobbieBF, Boshe99, Nxploited.

AI-analyzed exploit summary This PoC exploits CVE-2024-25092, a missing authorization vulnerability in NextMove Lite (<= 2.17.0), allowing authenticated attackers (subscriber+) to install and activate arbitrary WordPress plugins via the 'xl_addon_installation' function.

Description

Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0.

Exploits (3)

nomisec WORKING POC 1 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-25092

This PoC exploits CVE-2024-25092, a missing authorization vulnerability in NextMove Lite (<= 2.17.0), allowing authenticated attackers (subscriber+) to install and activate arbitrary WordPress plugins via the 'xl_addon_installation' function.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: NextMove Lite – Thank You Page for WooCommerce <= 2.17.0
Auth required
Prerequisites: Valid WordPress credentials (subscriber+) · Target site with vulnerable plugin installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2024-25092

The repository contains functional exploit code for CVE-2024-25092, targeting a WordPress plugin (3DPrint Lite 1.9.1.4) with an arbitrary file upload vulnerability. The Python script demonstrates the ability to upload a malicious file to a vulnerable target, confirming the exploit's effectiveness.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin 3DPrint Lite 1.9.1.4
No auth needed
Prerequisites: target URL · malicious file to upload
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC
by Nxploited · poc
https://github.com/Nxploited/CVE-2024-25092

This Python script exploits CVE-2024-25092, a missing authorization vulnerability in the WordPress NextMove Lite plugin (versions <= 2.17.0), allowing authenticated users with subscriber-level permissions to install and activate arbitrary plugins.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: WordPress NextMove Lite plugin versions <= 2.17.0
Auth required
Prerequisites: Valid WordPress credentials with subscriber-level access or higher · Target site running vulnerable version of NextMove Lite plugin
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.7145
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (2)
xlplugins/nextmove < 2.18.0
XLPlugins/NextMove Lite < 2.17.0
Published Jun 09, 2024
Tracked Since Feb 18, 2026