CVE-2023-25989
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2023-25989 is a Cross-Site Request Forgery (CSRF) vulnerability affecting multiple plugins by Meks, including Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, and Meks Easy Ads Widget. A malicious actor could exploit this issue to dismiss or manipulate pop-ups, potentially leading to unintended actions or unauthorized changes on affected WordPress sites. Users are advised to update these plugins to their latest versions to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Mekshq