CVE-2023-25989
EUVD-2023-2987603.10.2023, 12:15
Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the popup.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mekshq | meks_audio_player | 𝑥 ≤ 1.2 |
| mekshq | meks_easy_ads_widget | 𝑥 ≤ 2.0.7 |
| mekshq | meks_easy_maps | 𝑥 ≤ 2.1.3 |
| mekshq | meks_easy_photo_feed_widget | 𝑥 ≤ 1.2.7 |
| mekshq | meks_simple_flickr_widget | 𝑥 ≤ 1.2 |
| mekshq | meks_smart_author_widget | 𝑥 ≤ 1.1.3 |
| mekshq | meks_smart_social_widget | 𝑥 ≤ 1.6 |
| mekshq | meks_themeforest_smart_widget | 𝑥 ≤ 1.4 |
| mekshq | meks_time_ago | 𝑥 ≤ 1.1.6 |
| mekshq | meks_video_importer | 𝑥 ≤ 1.0.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References