2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14581MEDIUM4.3The HAPPY – Helpdesk Support Ticket System plugin for WordPress is vulnerable to authorization bypass due to a missing c...
CVE-2025-14542HIGH7.5The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endp...
CVE-2025-14540MEDIUM4.3The Userback plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ...
CVE-2025-14539MEDIUM5.4The The Shortcode Ajax plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and in...
CVE-2025-14508MEDIUM6.5The MediaCommander – Bring Folders to Media, Posts, and Pages plugin for WordPress is vulnerable to unauthorized data de...
CVE-2025-14477MEDIUM4.9The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.0 due to ...
CVE-2025-14476HIGH8.8The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all ver...
CVE-2025-14475HIGH8.1The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all vers...
CVE-2025-14462MEDIUM4.3The Lucky Draw Contests plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2025-14454MEDIUM4.3The Image Slider by Ays- Responsive Slider and Carousel plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2025-14451MEDIUM4.7The Solutions Ad Manager plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.0.0...
CVE-2025-14447MEDIUM4.3The AnnunciFunebri Impresa plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa...
CVE-2025-14446MEDIUM5.4The Popup Builder (Easy Notify Lite) plugin for WordPress is vulnerable to unauthorized modification of data due to a mi...
CVE-2025-14440CRITICAL9.8The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2...
CVE-2025-14397HIGH8.8The Postem Ipsum plugin for WordPress is vulnerable to unauthorized modification of data to Privilege Escalation due to ...
CVE-2025-14395MEDIUM4.3The Popover Windows plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2025-14394MEDIUM4.3The Popover Windows plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1...
CVE-2025-14378MEDIUM4.4The Quick Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi...
CVE-2025-14367MEDIUM5.3The Easy Theme Options plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,...
CVE-2025-14366MEDIUM5.3The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inc...
CVE-2025-14365MEDIUM5.3The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inc...
CVE-2025-14288MEDIUM4.3The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga...
CVE-2025-14278MEDIUM6.4The HT Slider for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_title' para...
CVE-2025-14056MEDIUM4.4The Custom Post Type UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter duri...
CVE-2025-14050MEDIUM4.9The Design Import/Export plugin for WordPress is vulnerable to SQL Injection via XML File Import in all versions up to, ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now