2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12019MEDIUM5.5The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image metadata in all versions ...
CVE-2025-12010MEDIUM6.5The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2025-11999MEDIUM5.3The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capa...
CVE-2025-11997MEDIUM5.3The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure i...
CVE-2025-11996MEDIUM5.3The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check...
CVE-2025-11988MEDIUM5.3The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including,...
CVE-2025-11986MEDIUM5.3The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This i...
CVE-2025-11894MEDIUM5.3The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2025-11891MEDIUM5.3The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2025-11886MEDIUM4.3The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2025-11882MEDIUM6.4The Simple Donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's simpledonate shortc...
CVE-2025-11874MEDIUM5.4The Slippy Slider – Responsive Touch Navigation Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2025-11873MEDIUM6.4The WP BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all ...
CVE-2025-11869MEDIUM6.4The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wrap_id` shortcode attrib...
CVE-2025-11863MEDIUM6.4The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode i...
CVE-2025-11860MEDIUM6.4The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in...
CVE-2025-11859MEDIUM6.4The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortco...
CVE-2025-11856MEDIUM6.4The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketw...
CVE-2025-11829MEDIUM6.4The Five9 Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'toolbar' attribute of the...
CVE-2025-11828MEDIUM6.4The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribu...
CVE-2025-11822MEDIUM6.4The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcod...
CVE-2025-11821MEDIUM6.4The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'woo_...
CVE-2025-11805MEDIUM6.4The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in al...
CVE-2025-11532MEDIUM5.3The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1...
CVE-2025-11129MEDIUM6.4The Include Fussball.de Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api' and 'typ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now