← Vulnerability feed

Vulnerability record · CVE-2024-1120 · published 1 March 2024

CVE-2024-1120: Xlplugins finale missing authorization vulnerability

Xlplugins · Finale

The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the download_tools_settings() function in all versions up to, and including, 2.17.0. This makes it possible for unauthenticated attackers to export system information that can aid attackers in an attack.

5.3 CVSS 3.1 Medium EPSS 0.53% · top 57.3% CWE-862 · Missing authorization
5.3CVSS 3.1 base score
0.53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the download_tools_settings() function in all versions up to, and including, 2.17.0. This makes it possible for unauthenticated attackers to export system information that can aid attackers in an attack.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-1120 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-30485Xlplugins finale missing authorization vulnerabilityMissing Authorization vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.EPSS 1.0%8.8CVE-2024-25092Xlplugins nextmove missing authorization vulnerabilityMissing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0.EPSS 1.4%7.1CVE-2025-52735Xlplugins nextmove cross-site scripting vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in XLPlugins NextMove Lite woo-thank-you-page-next…EPSS 0.30%6.5CVE-2025-62969Xlplugins nextmove cross-site scripting vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in XLPlugins NextMove Lite woo-thank-you-page-next…EPSS 0.17%6.5CVE-2023-47180Xlplugins finale missing authorization vulnerabilityMissing Authorization vulnerability in XLPlugins Finale Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec…EPSS 0.40%5.4CVE-2024-12589Xlplugins finale cross-site scripting vulnerabilityThe Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via th…EPSS 0.26%4.3CVE-2024-10860Xlplugins nextmove missing authorization vulnerabilityThe NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of data due to a missing capability …EPSS 0.27%4.3CVE-2024-32104Xlplugins nextmove cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.18.1.EPSS 0.75%

Source: NIST National Vulnerability Database (record CVE-2024-1120), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.