2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14165MEDIUM4.3The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2025-14162MEDIUM4.3The BMLT WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-14161MEDIUM4.3The Truefy Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-14160MEDIUM4.3The Upcoming for Calendly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-14158MEDIUM4.3The Coding Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-14143MEDIUM6.4The Ayo Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' parameter of the ay...
CVE-2025-14138MEDIUM6.1The WPLG Default Mail From plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S...
CVE-2025-14137MEDIUM6.1The Simple AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']`...
CVE-2025-14132MEDIUM6.1The Category Dropdown List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S...
CVE-2025-14129MEDIUM6.1The Like DisLike Voting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF...
CVE-2025-14125MEDIUM6.1The Complag plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable...
CVE-2025-14119MEDIUM6.4The App Landing Template Blocks for WPBakery (Visual Composer) Page Builder plugin for WordPress is vulnerable to Stored...
CVE-2025-14064MEDIUM5.4The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capabi...
CVE-2025-14062MEDIUM4.3The Animated Pixel Marquee Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery via the 'marquee' pa...
CVE-2025-14048MEDIUM4.4The SimplyConvert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'simplyconvert_hash' option ...
CVE-2025-14045MEDIUM4.3The URL Media Uploader plugin for WordPress is vulnerable to unauthorized safe file uploads due to a missing capability ...
CVE-2025-14044HIGH8.1The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, ...
CVE-2025-14035MEDIUM4.4The DebateMaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color options in the plugin s...
CVE-2025-14032MEDIUM6.4The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in th...
CVE-2025-13989MEDIUM6.4The WP Dropzone plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callback' shortcode attribute...
CVE-2025-13988MEDIUM6.1The 评论小秘书 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable i...
CVE-2025-13987MEDIUM4.3The Purchase and Expense Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-13975MEDIUM4.4The Contact Form 7 with ChatWork plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_token' a...
CVE-2025-13972MEDIUM4.9The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file read via the 'wht_download_big_object_origin' para...
CVE-2025-13971MEDIUM4.4The TWW Protein Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Header' setting in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now