2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11976 | MEDIUM | 4.3 | 0.1% | Oct 25, 2025 | The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)... |
| CVE-2025-11893 | MEDIUM | 6.5 | 0.3% | Oct 25, 2025 | The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul... |
| CVE-2025-11875 | MEDIUM | 6.4 | 0.2% | Oct 25, 2025 | The SpendeOnline.org plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spendeonline' s... |
| CVE-2025-11497 | MEDIUM | 4.3 | 0.2% | Oct 25, 2025 | The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an... |
| CVE-2025-11255 | MEDIUM | 4.3 | 0.2% | Oct 25, 2025 | The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to unauthorized modification of data d... |
| CVE-2025-10637 | MEDIUM | 5.3 | 0.3% | Oct 25, 2025 | The Social Feed Gallery plugin for WordPress is vulnerable to Information Exposure in versions less than, or equal to, 4... |
| CVE-2025-10580 | MEDIUM | 6.4 | 0.2% | Oct 25, 2025 | The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2025-8666 | MEDIUM | 6.4 | 0.2% | Oct 25, 2025 | The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple pa... |
| CVE-2025-8588 | MEDIUM | 6.4 | 0.2% | Oct 25, 2025 | The Gutenberg Blocks – PublishPress Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Ma... |
| CVE-2025-8413 | MEDIUM | 6.4 | 0.2% | Oct 25, 2025 | The Listeo theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `soundcloud` shortcode in v... |
| CVE-2025-6680 | MEDIUM | 4.3 | 0.2% | Oct 25, 2025 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposur... |
| CVE-2025-6639 | MEDIUM | 5.4 | 0.2% | Oct 25, 2025 | The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Re... |
| CVE-2025-12005 | MEDIUM | 4.3 | 0.2% | Oct 25, 2025 | The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to unauthorized ... |
| CVE-2025-11879 | MEDIUM | 6.5 | 0.3% | Oct 25, 2025 | The GenerateBlocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o... |
| CVE-2025-11564 | MEDIUM | 5.3 | 0.3% | Oct 25, 2025 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of ... |
| CVE-2025-11269 | MEDIUM | 5.3 | 0.3% | Oct 25, 2025 | The Product Filter by WBW plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2025-10737 | MEDIUM | 6.4 | 0.2% | Oct 25, 2025 | The Open Source Genesis Framework theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's short... |
| CVE-2025-10694 | MEDIUM | 5.3 | 0.2% | Oct 25, 2025 | The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnera... |
| CVE-2025-11823 | MEDIUM | 5.4 | 0.2% | Oct 25, 2025 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is... |
| CVE-2025-10579 | MEDIUM | 5.3 | 0.3% | Oct 25, 2025 | The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due t... |
| CVE-2025-11760 | MEDIUM | 5.3 | 0.3% | Oct 25, 2025 | The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposu... |
| CVE-2025-12194 | MEDIUM | 5.9 | 0.1% | Oct 24, 2025 | Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips ... |
| CVE-2025-62723 | MEDIUM | 4.3 | 0.3% | Oct 24, 2025 | FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.23.2, any authenticated user ca... |
| CVE-2025-60419 | MEDIUM | 6.2 | 0.1% | Oct 24, 2025 | An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authentica... |
| CVE-2025-60729 | MEDIUM | 5.3 | 0.3% | Oct 24, 2025 | PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now