2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14462 | MEDIUM | 4.3 | 0.1% | Dec 13, 2025 | The Lucky Draw Contests plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2025-14454 | MEDIUM | 4.3 | 0.1% | Dec 13, 2025 | The Image Slider by Ays- Responsive Slider and Carousel plugin for WordPress is vulnerable to Cross-Site Request Forgery... |
| CVE-2025-14451 | MEDIUM | 4.7 | 0.2% | Dec 13, 2025 | The Solutions Ad Manager plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.0.0... |
| CVE-2025-14447 | MEDIUM | 4.3 | 0.2% | Dec 13, 2025 | The AnnunciFunebri Impresa plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa... |
| CVE-2025-14446 | MEDIUM | 5.4 | 0.2% | Dec 13, 2025 | The Popup Builder (Easy Notify Lite) plugin for WordPress is vulnerable to unauthorized modification of data due to a mi... |
| CVE-2025-14395 | MEDIUM | 4.3 | 0.2% | Dec 13, 2025 | The Popover Windows plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2025-14394 | MEDIUM | 4.3 | 0.1% | Dec 13, 2025 | The Popover Windows plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1... |
| CVE-2025-14378 | MEDIUM | 4.4 | 0.2% | Dec 13, 2025 | The Quick Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi... |
| CVE-2025-14367 | MEDIUM | 5.3 | 0.2% | Dec 13, 2025 | The Easy Theme Options plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,... |
| CVE-2025-14366 | MEDIUM | 5.3 | 0.2% | Dec 13, 2025 | The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inc... |
| CVE-2025-14365 | MEDIUM | 5.3 | 0.2% | Dec 13, 2025 | The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inc... |
| CVE-2025-14288 | MEDIUM | 4.3 | 0.2% | Dec 13, 2025 | The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga... |
| CVE-2025-14278 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The HT Slider for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_title' para... |
| CVE-2025-14056 | MEDIUM | 4.4 | 0.3% | Dec 13, 2025 | The Custom Post Type UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter duri... |
| CVE-2025-14050 | MEDIUM | 4.9 | 0.3% | Dec 13, 2025 | The Design Import/Export plugin for WordPress is vulnerable to SQL Injection via XML File Import in all versions up to, ... |
| CVE-2025-13705 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The Custom Frames plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter of the 'cu... |
| CVE-2025-13403 | MEDIUM | 4.3 | 0.2% | Dec 13, 2025 | The Employee Spotlight – Team Member Showcase & Meet the Team Plugin for WordPress is vulnerable to unauthorized trackin... |
| CVE-2025-13093 | MEDIUM | 5.3 | 0.2% | Dec 13, 2025 | The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized modifi... |
| CVE-2025-13092 | MEDIUM | 5.3 | 0.2% | Dec 13, 2025 | The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized access... |
| CVE-2025-12512 | MEDIUM | 4.3 | 0.3% | Dec 13, 2025 | The GenerateBlocks plugin for WordPress is vulnerable to information exposure due to missing object-level authorization ... |
| CVE-2025-12362 | MEDIUM | 5.3 | 0.2% | Dec 13, 2025 | The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulne... |
| CVE-2025-12109 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2025-12077 | MEDIUM | 6.1 | 0.2% | Dec 13, 2025 | The WP to LinkedIn Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in ... |
| CVE-2025-12076 | MEDIUM | 6.1 | 0.2% | Dec 13, 2025 | The Social Media Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage param... |
| CVE-2025-11970 | MEDIUM | 4.4 | 0.2% | Dec 13, 2025 | The Emplibot – AI Content Writer with Keyword Research, Infographics, and Linking | SEO Optimized | Fully Automated plug... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now