CVE-2023-25989: Mekshq Meks Audio Player

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the popup.

Affected products

  • Mekshq Meks Audio Player: up to and including 1.2
  • Mekshq Meks Easy Ads Widget: up to and including 2.0.7
  • Mekshq Meks Easy Maps: up to and including 2.1.3
  • Mekshq Meks Easy Photo Feed Widget: up to and including 1.2.7
  • Mekshq Meks Simple Flickr Widget: up to and including 1.2
  • Mekshq Meks Smart Author Widget: up to and including 1.1.3
  • Mekshq Meks Smart Social Widget: up to and including 1.6
  • Mekshq Meks Themeforest Smart Widget: up to and including 1.4
  • Mekshq Meks Time Ago: up to and including 1.1.6
  • Mekshq Meks Video Importer: up to and including 1.0.10

Published 2023-10-03. Last modified 2026-06-17.