Vulnerabilities > Mekshq > Meks Easy Photo Feed Widget > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-03-14 CVE-2021-24958 Unspecified vulnerability in Mekshq Meks Easy Photo Feed Widget
The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF checks in the meks_save_business_selected_account AJAX action, available to any authenticated user, and does not escape some of the settings.
network
low complexity
mekshq
5.4