CVE detail
CVE-2023-25989 — CVE-2023-25989
Published 2023-10-03 · Modified 2026-06-17 · Vendor mekshq · Product meks_audio_player · Source nvd
MEDIUM
severity
CVSS-derived band
0.0043
EPSS probability
exploitation probability, 30d
36.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the popup.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References