Mekshq develops a focused line of WordPress widgets centered on content display and social integration, including ad management, photo feeds, author profiles, and map embedding functionality. The vulnerability profile is dominated by application-layer input-handling weaknesses, particularly cross-site scripting and cross-site request forgery, which recur across the widget portfolio and reflect the web-form and user-generated-content exposure inherent to WordPress plugins. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mekshq over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25989HIGH Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, M | Oct 3, 2023 | 8.8 | 24 | NO | NO |
CVE-2021-24958MEDIUM The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF checks in the meks_save_business_selected_account AJAX action, available to any auth | Mar 14, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-4562MEDIUM The Meks Flexible Shortcodes WordPress plugin before 1.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow | Feb 13, 2023 | 5.4 | 19 | NO | NO |
CVE-2022-2574MEDIUM The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored C | Oct 17, 2022 | 4.8 | 19 | NO | NO |
CVE-2024-37548MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Meks Meks Easy Ads Widget allows Stored XSS.This issue affects Meks Eas | Jul 21, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-37958MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Meks Meks Smart Author Widget allows Stored XSS.This issue affects Meks | Jul 20, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-0664MEDIUM The Meks Smart Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meks Smart Social Widget in all versions up to, and including, 1.6.3 due to i | Jan 27, 2024 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mekshq.
Media articles that mention a CVE ID that affects a product developed by Mekshq — matched by CVE ID, not by vendor name.