
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62084 is a Cross-Site Request Forgery (CSRF) vulnerability in the iNext Woo Pincode Checker WordPress plugin, developed by Imdad Next Web. It affects all versions from n/a through 2.3.1 (inclusive) and was discovered by researcher Muhammad Nur Ibnu Hubab on October 27, 2025, and publicly disclosed on December 31, 2025. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Patchstack (Patchstack).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery) and stems from the plugin's failure to implement or properly validate CSRF tokens (nonces) on sensitive state-changing requests. An unauthenticated attacker can craft a malicious web page or link that, when visited by an authenticated WordPress administrator or privileged user, silently submits a forged request to the plugin's endpoints — modifying pincode-related settings without the victim's knowledge. Exploitation requires no special privileges from the attacker but does require user interaction (a privileged user must be tricked into triggering the forged request) (Patchstack).
Successful exploitation allows an attacker to force higher-privileged users (such as WooCommerce store administrators) to execute unwanted actions under their current authentication context, primarily affecting data integrity by modifying pincode delivery zone settings. There is no direct confidentiality or availability impact (C:N/A:N per the CVSS vector), but unauthorized changes to pincode configurations could disrupt WooCommerce store operations or enable fraudulent order processing. The scope is limited to the affected WordPress installation (Patchstack).
As of the disclosure date (December 31, 2025), no official patched version has been released by the plugin developer Imdad Next Web. Site administrators should remove or deactivate the iNext Woo Pincode Checker plugin until a patched version is available. As a compensating control, web application firewalls (WAF) with WordPress-specific rulesets — such as Patchstack's virtual patching — can block exploitation attempts. Administrators should also ensure that privileged users follow safe browsing practices and avoid clicking unsolicited links while authenticated to the WordPress admin panel (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."