2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14294MEDIUM5.3The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2025-14167MEDIUM4.3The Remove Post Type Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-14076MEDIUM6.1The iXML – Google XML sitemap generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'iX...
CVE-2025-13930MEDIUM5.3The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass...
CVE-2025-13864MEDIUM5.3The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up...
CVE-2025-13842MEDIUM5.3The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions ...
CVE-2025-13738MEDIUM6.4The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` s...
CVE-2025-13732MEDIUM6.4The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin...
CVE-2025-13617MEDIUM6.4The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a13_alt_lin...
CVE-2025-13612MEDIUM6.4The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2025-13587MEDIUM6.5The Two Factor (2FA) Authentication via Email plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in ...
CVE-2025-13438MEDIUM4.3The Page Title, Description & Open Graph Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2025-13413MEDIUM4.3The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ...
CVE-2025-13113MEDIUM5.3The Web Accessibility by accessiBe plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2025-13091MEDIUM4.3The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on ...
CVE-2025-13079MEDIUM5.3The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to au...
CVE-2025-13048MEDIUM6.4The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-12884MEDIUM4.3The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to authorization bypass in versions up to, an...
CVE-2025-12500MEDIUM5.3The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limi...
CVE-2025-12451MEDIUM4.4The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versi...
CVE-2025-12448MEDIUM6.4The Smartsupp – live chat, AI shopping assistant and chatbots plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2025-12375MEDIUM6.4The Printful Integration for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio...
CVE-2025-12172MEDIUM4.3The Mailchimp List Subscribe Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2025-12117MEDIUM6.4The Renden theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, an...
CVE-2025-12116MEDIUM6.4The Drift theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now