2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-11976MEDIUM4.3The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)...
CVE-2025-11893MEDIUM6.5The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul...
CVE-2025-11875MEDIUM6.4The SpendeOnline.org plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spendeonline' s...
CVE-2025-11497MEDIUM4.3The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2025-11255MEDIUM4.3The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2025-10637MEDIUM5.3The Social Feed Gallery plugin for WordPress is vulnerable to Information Exposure in versions less than, or equal to, 4...
CVE-2025-10580MEDIUM6.4The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2025-8666MEDIUM6.4The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple pa...
CVE-2025-8588MEDIUM6.4The Gutenberg Blocks – PublishPress Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Ma...
CVE-2025-8413MEDIUM6.4The Listeo theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `soundcloud` shortcode in v...
CVE-2025-6680MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposur...
CVE-2025-6639MEDIUM5.4The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Re...
CVE-2025-12005MEDIUM4.3The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to unauthorized ...
CVE-2025-11879MEDIUM6.5The GenerateBlocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o...
CVE-2025-11564MEDIUM5.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of ...
CVE-2025-11269MEDIUM5.3The Product Filter by WBW plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2025-10737MEDIUM6.4The Open Source Genesis Framework theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's short...
CVE-2025-10694MEDIUM5.3The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnera...
CVE-2025-11823MEDIUM5.4The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is...
CVE-2025-10579MEDIUM5.3The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due t...
CVE-2025-11760MEDIUM5.3The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposu...
CVE-2025-12194MEDIUM5.9Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips ...
CVE-2025-62723MEDIUM4.3FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.23.2, any authenticated user ca...
CVE-2025-60419MEDIUM6.2An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authentica...
CVE-2025-60729MEDIUM5.3PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now