2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13694 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. ... |
| CVE-2025-13667 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input fiel... |
| CVE-2025-13657 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The HelpDesk contact form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-13531 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Stylish Order Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'product_name' ... |
| CVE-2025-13529 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The Unify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t... |
| CVE-2025-13527 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The xShare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1.... |
| CVE-2025-13521 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The WP Status Notifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2025-13520 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The MTCaptcha WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2025-13519 | MEDIUM | 6.1 | 0.1% | Jan 7, 2026 | The SVG Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-13497 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Recras WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'recrasname' shortcode at... |
| CVE-2025-13496 | MEDIUM | 5.3 | 0.3% | Jan 7, 2026 | The Moosend Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2025-13493 | HIGH | 7.5 | 0.3% | Jan 7, 2026 | The Latest Registered Users plugin for WordPress is vulnerable to unauthorized user data export in all versions up to, a... |
| CVE-2025-13419 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to unautho... |
| CVE-2025-13418 | MEDIUM | 6.4 | 0.6% | Jan 7, 2026 | The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'plan_icons' para... |
| CVE-2025-13371 | HIGH | 8.6 | 0.4% | Jan 7, 2026 | The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including... |
| CVE-2025-13369 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Premmerce WooCommerce Customers Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the... |
| CVE-2025-12958 | LOW | 2.7 | 0.2% | Jan 7, 2026 | The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized modification of data due to an i... |
| CVE-2025-12648 | MEDIUM | 5.3 | 0.3% | Jan 7, 2026 | The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and includin... |
| CVE-2025-12540 | MEDIUM | 4.7 | 0.2% | Jan 7, 2026 | The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Sensitive Information Exposure in all... |
| CVE-2025-12449 | MEDIUM | 5.4 | 0.2% | Jan 7, 2026 | The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and dis... |
| CVE-2025-12030 | MEDIUM | 4.3 | 0.3% | Jan 7, 2026 | The ACF to REST API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and in... |
| CVE-2025-11877 | HIGH | 7.5 | 0.3% | Jan 7, 2026 | The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed... |
| CVE-2025-11235 | HIGH | 7.5 | 0.2% | Jan 7, 2026 | Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MO... |
| CVE-2025-0980 | MEDIUM | 6.4 | 0.1% | Jan 7, 2026 | Nokia SR Linux is vulnerable to an authentication vulnerability allowing unauthorized access to the JSON-RPC service. W... |
| CVE-2025-31642 | HIGH | 7.1 | 0.1% | Jan 7, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dasinfomedia WPCHU... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now