CVE-2023-25989
Cross-Site Request Forgery (CSRF) vulnerability in multiple WordPress plugins by Meks
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the popup.
Vulnerabilidad de Cross-Site Request Forgery (CSRF) en Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, complementos de Meks Smart Social Widget que llevan a descartar o a la ventana emergente.
The Meks Smart Social Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the meks_remove_notification function. This makes it possible for unauthenticated attackers to dismiss admin notices via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the popup.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-02-17 CVE Reserved
- 2023-07-26 CVE Published
- 2024-08-02 CVE Updated
- 2025-01-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
- CAPEC-62: Cross Site Request Forgery
References (10)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mekshq Search vendor "Mekshq" | Meks Audio Player Search vendor "Mekshq" for product "Meks Audio Player" | <= 1.2 Search vendor "Mekshq" for product "Meks Audio Player" and version " <= 1.2" | wordpress |
Affected
| ||||||
Mekshq Search vendor "Mekshq" | Meks Easy Ads Widget Search vendor "Mekshq" for product "Meks Easy Ads Widget" | <= 2.0.7 Search vendor "Mekshq" for product "Meks Easy Ads Widget" and version " <= 2.0.7" | wordpress |
Affected
| ||||||
Mekshq Search vendor "Mekshq" | Meks Easy Maps Search vendor "Mekshq" for product "Meks Easy Maps" | <= 2.1.3 Search vendor "Mekshq" for product "Meks Easy Maps" and version " <= 2.1.3" | wordpress |
Affected
| ||||||
Mekshq Search vendor "Mekshq" | Meks Easy Photo Feed Widget Search vendor "Mekshq" for product "Meks Easy Photo Feed Widget" | <= 1.2.7 Search vendor "Mekshq" for product "Meks Easy Photo Feed Widget" and version " <= 1.2.7" | wordpress |
Affected
| ||||||
Mekshq Search vendor "Mekshq" | Meks Simple Flickr Widget Search vendor "Mekshq" for product "Meks Simple Flickr Widget" | <= 1.2 Search vendor "Mekshq" for product "Meks Simple Flickr Widget" and version " <= 1.2" | wordpress |
Affected
| ||||||
Mekshq Search vendor "Mekshq" | Meks Smart Author Widget Search vendor "Mekshq" for product "Meks Smart Author Widget" | <= 1.1.3 Search vendor "Mekshq" for product "Meks Smart Author Widget" and version " <= 1.1.3" | wordpress |
Affected
| ||||||
Mekshq Search vendor "Mekshq" | Meks Smart Social Widget Search vendor "Mekshq" for product "Meks Smart Social Widget" | <= 1.6 Search vendor "Mekshq" for product "Meks Smart Social Widget" and version " <= 1.6" | wordpress |
Affected
| ||||||
Mekshq Search vendor "Mekshq" | Meks Themeforest Smart Widget Search vendor "Mekshq" for product "Meks Themeforest Smart Widget" | <= 1.4 Search vendor "Mekshq" for product "Meks Themeforest Smart Widget" and version " <= 1.4" | wordpress |
Affected
| ||||||
Mekshq Search vendor "Mekshq" | Meks Time Ago Search vendor "Mekshq" for product "Meks Time Ago" | <= 1.1.6 Search vendor "Mekshq" for product "Meks Time Ago" and version " <= 1.1.6" | wordpress |
Affected
| ||||||
Mekshq Search vendor "Mekshq" | Meks Video Importer Search vendor "Mekshq" for product "Meks Video Importer" | <= 1.0.10 Search vendor "Mekshq" for product "Meks Video Importer" and version " <= 1.0.10" | wordpress |
Affected
|