2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12526 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2025-12132 | MEDIUM | 4.3 | 0.1% | Nov 11, 2025 | The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ... |
| CVE-2025-12126 | MEDIUM | 5.4 | 0.2% | Nov 11, 2025 | The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,... |
| CVE-2025-12021 | MEDIUM | 6.1 | 0.3% | Nov 11, 2025 | The WP-OAuth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error_description' parameter ... |
| CVE-2025-12020 | MEDIUM | 4.9 | 0.2% | Nov 11, 2025 | The Double the Donation – A workplace giving tool to help your fundraising efforts plugin for WordPress is vulnerable to... |
| CVE-2025-12019 | MEDIUM | 5.5 | 0.4% | Nov 11, 2025 | The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image metadata in all versions ... |
| CVE-2025-12010 | MEDIUM | 6.5 | 0.3% | Nov 11, 2025 | The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2025-11999 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capa... |
| CVE-2025-11997 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure i... |
| CVE-2025-11996 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check... |
| CVE-2025-11988 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including,... |
| CVE-2025-11986 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This i... |
| CVE-2025-11894 | MEDIUM | 5.3 | 0.2% | Nov 11, 2025 | The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2025-11891 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2025-11886 | MEDIUM | 4.3 | 0.1% | Nov 11, 2025 | The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-11882 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Simple Donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's simpledonate shortc... |
| CVE-2025-11874 | MEDIUM | 5.4 | 0.2% | Nov 11, 2025 | The Slippy Slider – Responsive Touch Navigation Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2025-11873 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The WP BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all ... |
| CVE-2025-11869 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wrap_id` shortcode attrib... |
| CVE-2025-11863 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode i... |
| CVE-2025-11860 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in... |
| CVE-2025-11859 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortco... |
| CVE-2025-11856 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketw... |
| CVE-2025-11829 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Five9 Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'toolbar' attribute of the... |
| CVE-2025-11828 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now