ZeroHour

CVE-2023-25989

CVSS 3.1
8.8 high
EPSS
<1%p37
Published
()
Modified
Description

Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the popup.

Vendors
mekshq
Products
meks audio player, meks easy ads widget, meks easy maps, meks easy photo feed widget, meks simple flickr widget, meks smart author widget, meks smart social widget, meks themeforest smart widget, meks time ago, meks video importer
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.