Description
Cross-Site Request Forgery (CSRF) vulnerability in Imdad Next Web iNext Woo Pincode Checker inext-woo-pincode-checker allows Cross Site Request Forgery.This issue affects iNext Woo Pincode Checker: from n/a through <= 2.3.1.
Published: 2025-12-31
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery (CSRF) flaw in the Imdad Next Web iNext Woo Pincode Checker plugin. The plugin fails to verify CSRF tokens, and the CVE description indicates that any request matching the plugin’s expected pattern is accepted. Based on this description, an attacker could trigger plugin actions that normally require an authenticated session, potentially causing unauthorized modifications to the data that the plugin handles. This compromise would affect the integrity of plugin‑managed data while leaving the overall WordPress installation unaffected unless the plugin performs critical configuration tasks.

Affected Systems

WordPress sites running the Imdad Next Web iNext Woo Pincode Checker plugin version 2.3.1 or older are impacted. The issue covers all versions from the earliest available through 2.3.1.

Risk and Exploitability

The CVSS score of 4.3 reflects moderate severity, and the EPSS score of less than 1% indicates a very low exploitation probability at the time of this analysis. The vulnerability is not in the CISA KEV catalog. While the CVE does not specify the exact attack path, CSRF usually requires a victim to be authenticated and to have an active session on the site; an attacker could embed a malicious form or link that submits a request to the vulnerable plugin endpoint. This inference is based on typical CSRF mechanisms, not on details supplied in the CVE.

Generated by OpenCVE AI on April 30, 2026 at 14:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Imdad Next Web iNext Woo Pincode Checker to a version newer than 2.3.1 to deploy the vendor‑provided CSRF protection.
  • If an immediate upgrade is not feasible, disable the plugin or restrict its administrative access to users with the highest privileges.
  • As a temporary safeguard, employ a WAF rule that blocks or verifies CSRF tokens for all POST requests targeting the plugin, or use a security plugin that adds CSRF tokens to forms.

Generated by OpenCVE AI on April 30, 2026 at 14:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Imdad Next Web iNext Woo Pincode Checker allows Cross Site Request Forgery.This issue affects iNext Woo Pincode Checker: from n/a through 2.3.1. Cross-Site Request Forgery (CSRF) vulnerability in Imdad Next Web iNext Woo Pincode Checker inext-woo-pincode-checker allows Cross Site Request Forgery.This issue affects iNext Woo Pincode Checker: from n/a through <= 2.3.1.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Imdad Next Web
Imdad Next Web inext Woo Pincode Checker
Wordpress
Wordpress wordpress
Vendors & Products Imdad Next Web
Imdad Next Web inext Woo Pincode Checker
Wordpress
Wordpress wordpress

Wed, 31 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 16:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Imdad Next Web iNext Woo Pincode Checker allows Cross Site Request Forgery.This issue affects iNext Woo Pincode Checker: from n/a through 2.3.1.
Title WordPress iNext Woo Pincode Checker plugin <= 2.3.1 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Imdad Next Web Inext Woo Pincode Checker
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:00.916Z

Reserved: 2025-10-07T15:34:50.699Z

Link: CVE-2025-62084

cve-icon Vulnrichment

Updated: 2025-12-31T16:49:10.355Z

cve-icon NVD

Status : Deferred

Published: 2025-12-31T16:15:44.130

Modified: 2026-04-23T15:34:30.650

Link: CVE-2025-62084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T14:30:06Z

Weaknesses