2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14294 | MEDIUM | 5.3 | 0.4% | Feb 19, 2026 | The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2025-14167 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | The Remove Post Type Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-14076 | MEDIUM | 6.1 | 0.3% | Feb 19, 2026 | The iXML – Google XML sitemap generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'iX... |
| CVE-2025-13930 | MEDIUM | 5.3 | 0.4% | Feb 19, 2026 | The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass... |
| CVE-2025-13864 | MEDIUM | 5.3 | 0.4% | Feb 19, 2026 | The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up... |
| CVE-2025-13842 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions ... |
| CVE-2025-13738 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` s... |
| CVE-2025-13732 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin... |
| CVE-2025-13617 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a13_alt_lin... |
| CVE-2025-13612 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2025-13587 | MEDIUM | 6.5 | 0.4% | Feb 19, 2026 | The Two Factor (2FA) Authentication via Email plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in ... |
| CVE-2025-13438 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | The Page Title, Description & Open Graph Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
| CVE-2025-13413 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ... |
| CVE-2025-13113 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | The Web Accessibility by accessiBe plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
| CVE-2025-13091 | MEDIUM | 4.3 | 0.3% | Feb 19, 2026 | The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on ... |
| CVE-2025-13079 | MEDIUM | 5.3 | 0.4% | Feb 19, 2026 | The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to au... |
| CVE-2025-13048 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-12884 | MEDIUM | 4.3 | 0.3% | Feb 19, 2026 | The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to authorization bypass in versions up to, an... |
| CVE-2025-12500 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limi... |
| CVE-2025-12451 | MEDIUM | 4.4 | 0.2% | Feb 19, 2026 | The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versi... |
| CVE-2025-12448 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The Smartsupp – live chat, AI shopping assistant and chatbots plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2025-12375 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The Printful Integration for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio... |
| CVE-2025-12172 | MEDIUM | 4.3 | 0.1% | Feb 19, 2026 | The Mailchimp List Subscribe Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2025-12117 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | The Renden theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, an... |
| CVE-2025-12116 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | The Drift theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now