2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9897MEDIUM4.3The AP Background plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-9895MEDIUM4.3The Notification Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2025-9892MEDIUM5.3The Restrict User Registration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2025-9889MEDIUM4.3The ContentMX Content Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ...
CVE-2025-9885MEDIUM4.3The MPWizard – Create Mercado Pago Payment Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2025-9884MEDIUM6.1The Mobile Site Redirect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-9876MEDIUM6.4The Ird Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irdslider' shortcode ...
CVE-2025-9875MEDIUM6.4The Event Tickets, RSVPs, Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 't...
CVE-2025-9859MEDIUM6.4The Fintelligence Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fintell...
CVE-2025-9858MEDIUM6.4The Auto Bulb Finder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'a...
CVE-2025-9854MEDIUM6.4The A Simple Multilanguage Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'as...
CVE-2025-9630MEDIUM4.3The WP SinoType plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-9372MEDIUM5.5The Ultimate Multi Design Video Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versio...
CVE-2025-9333MEDIUM5.5The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t...
CVE-2025-9332MEDIUM5.5The Interactive Human Anatomy with Clickable Body Parts plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-9206MEDIUM6.4The Meks Easy Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title field in all ver...
CVE-2025-9204MEDIUM6.4The X Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Youtube Video ID fi...
CVE-2025-9199MEDIUM6.5The Woo superb slideshow transition gallery with random effect plugin for WordPress is vulnerable to SQL Injection via t...
CVE-2025-9198MEDIUM6.5The Wp cycle text announcement plugin for WordPress is vulnerable to SQL Injection via the 'cycle-text' shortcode in all...
CVE-2025-9194MEDIUM4.3The Constructor theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2025-9130MEDIUM6.4The Unify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's unify_checkou...
CVE-2025-9129MEDIUM6.4The Flexi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's flexi-form-ta...
CVE-2025-9080MEDIUM6.4The Generic Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget fields in ver...
CVE-2025-9077MEDIUM6.4The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Animated ...
CVE-2025-9045MEDIUM6.4The Easy Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameter...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now