CVE-2023-25989
Summary
| CVE | CVE-2023-25989 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-03 12:15:00 UTC |
| Updated | 2023-10-16 17:45:00 UTC |
| Description | Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the popup. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mekshq | Meks Audio Player | All | All | All | All |
| Application | Mekshq | Meks Easy Ads Widget | All | All | All | All |
| Application | Mekshq | Meks Easy Maps | All | All | All | All |
| Application | Mekshq | Meks Easy Photo Feed Widget | All | All | All | All |
| Application | Mekshq | Meks Simple Flickr Widget | All | All | All | All |
| Application | Mekshq | Meks Smart Author Widget | All | All | All | All |
| Application | Mekshq | Meks Smart Social Widget | All | All | All | All |
| Application | Mekshq | Meks Themeforest Smart Widget | All | All | All | All |
| Application | Mekshq | Meks Time Ago | All | All | All | All |
| Application | Mekshq | Meks Video Importer | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WordPress Meks Easy Ads Widget plugin <= 2.0.7 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack | MISC | patchstack.com | |
| WordPress Meks ThemeForest Smart Widget plugin <= 1.4 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack | MISC | patchstack.com | |
| WordPress Meks Audio Player plugin <= 1.2 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack | MISC | patchstack.com | |
| WordPress Meks Smart Social Widget plugin <= 1.6 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack | MISC | patchstack.com | |
| WordPress Meks Easy Photo Feed Widget plugin <= 1.2.7 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack | MISC | patchstack.com | |
| WordPress Meks Easy Maps plugin <= 2.1.3 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack | MISC | patchstack.com | |
| WordPress Meks Time Ago plugin <= 1.1.6 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack | MISC | patchstack.com | |
| WordPress Meks Video Importer plugin <= 1.0.10 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack | MISC | patchstack.com | |
| WordPress Meks Smart Author Widget plugin <= 1.1.3 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack | MISC | patchstack.com | |
| WordPress Meks Simple Flickr Widget plugin <= 1.2 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack | MISC | patchstack.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.