Description
The IMAQ Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the URL structure settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's URL structure settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published: 2025-12-12
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of WordPress plugin settings via Cross‑Site Request Forgery
Action: Patch
AI Analysis

Impact

The IMAQ Core plugin contains a Cross‑Site Request Forgery vulnerability that allows an unauthenticated attacker to change the plugin’s URL structure settings. The flaw arises from missing nonce verification during the update process, enabling a forged request to execute when an administrator clicks a malicious link. This weakness permits the attacker to alter how the plugin rewrites URLs, potentially disrupting site navigation or redirecting traffic.

Affected Systems

WordPress sites running IMAQ Core 1.2.1 or earlier are affected. The plugin is issued by imaqpress under the product name IMAQ CORE. No specific version numbers beyond 1.2.1 are mentioned as vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates low‑medium severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. An attacker can exploit this weakness by directing a site administrator to visit a crafted link that submits a CSRF request to update the URL structure settings. Because the attacker need not authenticate, the impact is limited to the scope of the plugin’s configuration, but it could disturb site functionality or enable further damage if other plugin settings are affected.

Generated by OpenCVE AI on April 21, 2026 at 17:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade IMAQ Core to a version newer than 1.2.1 that includes proper nonce validation for URL structure updates.
  • If an upgrade is not immediately possible, restrict access to the URL structure settings page by applying role‑based permissions or disabling the settings through WordPress configuration.
  • Educate administrators against clicking untrusted links and monitor for anomalous admin activity to detect potential CSRF attempts.

Generated by OpenCVE AI on April 21, 2026 at 17:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 15 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Dec 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 12 Dec 2025 03:45:00 +0000

Type Values Removed Values Added
Description The IMAQ Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the URL structure settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's URL structure settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Title IMAQ Core <= 1.2.1 - Cross-Site Request Forgery to URL Structure Update
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:58:26.023Z

Reserved: 2025-11-18T16:48:31.220Z

Link: CVE-2025-13363

cve-icon Vulnrichment

Updated: 2025-12-12T20:59:46.449Z

cve-icon NVD

Status : Deferred

Published: 2025-12-12T04:15:41.490

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-13363

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T17:30:37Z

Weaknesses