2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14540MEDIUM4.3The Userback plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ...
CVE-2025-14539MEDIUM5.4The The Shortcode Ajax plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and in...
CVE-2025-14508MEDIUM6.5The MediaCommander – Bring Folders to Media, Posts, and Pages plugin for WordPress is vulnerable to unauthorized data de...
CVE-2025-14477MEDIUM4.9The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.0 due to ...
CVE-2025-14462MEDIUM4.3The Lucky Draw Contests plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2025-14454MEDIUM4.3The Image Slider by Ays- Responsive Slider and Carousel plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2025-14451MEDIUM4.7The Solutions Ad Manager plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.0.0...
CVE-2025-14447MEDIUM4.3The AnnunciFunebri Impresa plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa...
CVE-2025-14446MEDIUM5.4The Popup Builder (Easy Notify Lite) plugin for WordPress is vulnerable to unauthorized modification of data due to a mi...
CVE-2025-14395MEDIUM4.3The Popover Windows plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2025-14394MEDIUM4.3The Popover Windows plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1...
CVE-2025-14378MEDIUM4.4The Quick Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi...
CVE-2025-14367MEDIUM5.3The Easy Theme Options plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,...
CVE-2025-14366MEDIUM5.3The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inc...
CVE-2025-14365MEDIUM5.3The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inc...
CVE-2025-14288MEDIUM4.3The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga...
CVE-2025-14278MEDIUM6.4The HT Slider for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_title' para...
CVE-2025-14056MEDIUM4.4The Custom Post Type UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter duri...
CVE-2025-14050MEDIUM4.9The Design Import/Export plugin for WordPress is vulnerable to SQL Injection via XML File Import in all versions up to, ...
CVE-2025-13705MEDIUM6.4The Custom Frames plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter of the 'cu...
CVE-2025-13403MEDIUM4.3The Employee Spotlight – Team Member Showcase & Meet the Team Plugin for WordPress is vulnerable to unauthorized trackin...
CVE-2025-13093MEDIUM5.3The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized modifi...
CVE-2025-13092MEDIUM5.3The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized access...
CVE-2025-12512MEDIUM4.3The GenerateBlocks plugin for WordPress is vulnerable to information exposure due to missing object-level authorization ...
CVE-2025-12362MEDIUM5.3The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulne...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now