2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12019 | MEDIUM | 5.5 | 0.4% | Nov 11, 2025 | The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image metadata in all versions ... |
| CVE-2025-12010 | MEDIUM | 6.5 | 0.3% | Nov 11, 2025 | The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2025-11999 | MEDIUM | 5.3 | 0.2% | Nov 11, 2025 | The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capa... |
| CVE-2025-11997 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure i... |
| CVE-2025-11996 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check... |
| CVE-2025-11988 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including,... |
| CVE-2025-11986 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This i... |
| CVE-2025-11894 | MEDIUM | 5.3 | 0.2% | Nov 11, 2025 | The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2025-11891 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2025-11886 | MEDIUM | 4.3 | 0.1% | Nov 11, 2025 | The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-11882 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Simple Donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's simpledonate shortc... |
| CVE-2025-11874 | MEDIUM | 5.4 | 0.2% | Nov 11, 2025 | The Slippy Slider – Responsive Touch Navigation Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2025-11873 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The WP BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all ... |
| CVE-2025-11869 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wrap_id` shortcode attrib... |
| CVE-2025-11863 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode i... |
| CVE-2025-11860 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in... |
| CVE-2025-11859 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortco... |
| CVE-2025-11856 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketw... |
| CVE-2025-11829 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Five9 Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'toolbar' attribute of the... |
| CVE-2025-11828 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribu... |
| CVE-2025-11822 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcod... |
| CVE-2025-11821 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'woo_... |
| CVE-2025-11805 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in al... |
| CVE-2025-11532 | MEDIUM | 5.3 | 0.2% | Nov 11, 2025 | The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1... |
| CVE-2025-11129 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Include Fussball.de Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api' and 'typ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now