2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13694MEDIUM5.3The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. ...
CVE-2025-13667MEDIUM6.4The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input fiel...
CVE-2025-13657MEDIUM4.3The HelpDesk contact form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-13531MEDIUM6.4The Stylish Order Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'product_name' ...
CVE-2025-13529MEDIUM5.3The Unify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t...
CVE-2025-13527MEDIUM4.3The xShare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1....
CVE-2025-13521MEDIUM4.3The WP Status Notifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2025-13520MEDIUM4.3The MTCaptcha WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2025-13519MEDIUM6.1The SVG Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-13497MEDIUM6.4The Recras WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'recrasname' shortcode at...
CVE-2025-13496MEDIUM5.3The Moosend Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2025-13493HIGH7.5The Latest Registered Users plugin for WordPress is vulnerable to unauthorized user data export in all versions up to, a...
CVE-2025-13419MEDIUM5.3The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to unautho...
CVE-2025-13418MEDIUM6.4The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'plan_icons' para...
CVE-2025-13371HIGH8.6The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2025-13369MEDIUM6.1The Premmerce WooCommerce Customers Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the...
CVE-2025-12958LOW2.7The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized modification of data due to an i...
CVE-2025-12648MEDIUM5.3The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and includin...
CVE-2025-12540MEDIUM4.7The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
CVE-2025-12449MEDIUM5.4The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and dis...
CVE-2025-12030MEDIUM4.3The ACF to REST API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and in...
CVE-2025-11877HIGH7.5The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed...
CVE-2025-11235HIGH7.5Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MO...
CVE-2025-0980MEDIUM6.4Nokia SR Linux is vulnerable to an authentication vulnerability allowing unauthorized access to the JSON-RPC service. W...
CVE-2025-31642HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dasinfomedia WPCHU...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now