2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12935 | MEDIUM | 6.4 | 0.3% | Nov 21, 2025 | The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin f... |
| CVE-2025-10054 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2025-10039 | MEDIUM | 4.3 | 0.3% | Nov 21, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Ref... |
| CVE-2025-12964 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Magical Products Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpdpr_title_tag'... |
| CVE-2025-12750 | MEDIUM | 4.9 | 0.3% | Nov 21, 2025 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to SQL Injection via the ... |
| CVE-2025-12066 | MEDIUM | 4.4 | 0.2% | Nov 21, 2025 | The WP Delete Post Copies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve... |
| CVE-2025-13149 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin fo... |
| CVE-2025-13141 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2025-12039 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versi... |
| CVE-2025-11973 | MEDIUM | 4.9 | 0.3% | Nov 21, 2025 | The 简数采集器 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.6.3 via the ... |
| CVE-2025-11826 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The WP Company Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the '... |
| CVE-2025-11808 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Shortcode for Google Street View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'streetvi... |
| CVE-2025-11803 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The WPSite Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'format' shortcode attrib... |
| CVE-2025-13142 | MEDIUM | 4.3 | 0.1% | Nov 21, 2025 | The Custom Post Type plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2025-13135 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The HotelRunner Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hotel... |
| CVE-2025-13134 | MEDIUM | 6.1 | 0.1% | Nov 21, 2025 | The AuthorSure plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.... |
| CVE-2025-12894 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Informa... |
| CVE-2025-12881 | MEDIUM | 5.4 | 0.1% | Nov 21, 2025 | The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in... |
| CVE-2025-12746 | MEDIUM | 6.1 | 0.2% | Nov 21, 2025 | The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all vers... |
| CVE-2025-12661 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Pollcaster Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in... |
| CVE-2025-12660 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Padlet Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'key' parameter in the 'w... |
| CVE-2025-12170 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | The Checkbox plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'w... |
| CVE-2025-12086 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in... |
| CVE-2025-11885 | MEDIUM | 6.1 | 0.2% | Nov 21, 2025 | The EchBay Admin Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_ebnonce' parame... |
| CVE-2025-11815 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now