MEDIUM · 4.3

CVE-2023-25989

Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed ...

Vulnerability Description

Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the popup.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
MekshqMeks Audio Player<= 1.2
MekshqMeks Easy Ads Widget<= 2.0.7
MekshqMeks Easy Maps<= 2.1.3
MekshqMeks Easy Photo Feed Widget<= 1.2.7
MekshqMeks Simple Flickr Widget<= 1.2
MekshqMeks Smart Author Widget<= 1.1.3
MekshqMeks Smart Social Widget<= 1.6
MekshqMeks Themeforest Smart Widget<= 1.4
MekshqMeks Time Ago<= 1.1.6
MekshqMeks Video Importer<= 1.0.10

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-25989?

CVE-2023-25989 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed ...

How severe is CVE-2023-25989?

CVE-2023-25989 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-25989?

Check the references section above for vendor advisories and patch information. Affected products include: Mekshq Meks Audio Player, Mekshq Meks Easy Ads Widget, Mekshq Meks Easy Maps, Mekshq Meks Easy Photo Feed Widget, Mekshq Meks Simple Flickr Widget.