2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-66061MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting ...
CVE-2025-66060MEDIUM5.3Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Explo...
CVE-2025-66059MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Craig Hewitt Seriously Simpl...
CVE-2025-66057MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Pa...
CVE-2025-66056MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Uncanny Owl Uncanny Automato...
CVE-2025-66053MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold enfo...
CVE-2025-12935MEDIUM6.4The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin f...
CVE-2025-10054MEDIUM4.3The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2025-10039MEDIUM4.3The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Ref...
CVE-2025-12964MEDIUM6.4The Magical Products Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpdpr_title_tag'...
CVE-2025-12750MEDIUM4.9The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to SQL Injection via the ...
CVE-2025-12066MEDIUM4.4The WP Delete Post Copies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve...
CVE-2025-13149MEDIUM4.3The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin fo...
CVE-2025-13141MEDIUM6.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2025-12039MEDIUM5.3The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versi...
CVE-2025-11973MEDIUM4.9The 简数采集器 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.6.3 via the ...
CVE-2025-11826MEDIUM6.4The WP Company Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the '...
CVE-2025-11808MEDIUM6.4The Shortcode for Google Street View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'streetvi...
CVE-2025-11803MEDIUM6.4The WPSite Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'format' shortcode attrib...
CVE-2025-13142MEDIUM4.3The Custom Post Type plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2025-13135MEDIUM6.4The HotelRunner Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hotel...
CVE-2025-13134MEDIUM6.1The AuthorSure plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2....
CVE-2025-12894MEDIUM5.3The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Informa...
CVE-2025-12881MEDIUM5.4The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in...
CVE-2025-12746MEDIUM6.1The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all vers...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now