2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13969MEDIUM6.4The Reviews Sorted plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'space' parameter of the [r...
CVE-2025-13966MEDIUM6.4The Paypal Payment Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttom_image' pa...
CVE-2025-13963MEDIUM6.4The FX Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fxcc_conve...
CVE-2025-13962MEDIUM6.4The Divelogs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'latestdive' shor...
CVE-2025-13961MEDIUM6.4The Data Visualizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'visualize' short...
CVE-2025-13960MEDIUM6.4The GPXpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gpxpress' shortcode in ...
CVE-2025-13906MEDIUM6.4The WP Flot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linechart' shortcode in ...
CVE-2025-13904MEDIUM6.4The WPGancio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gancio-event' shortcode...
CVE-2025-13889MEDIUM6.4The Simple Nivo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode paramete...
CVE-2025-13885MEDIUM6.4The Zenost Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' and 'target' para...
CVE-2025-13884MEDIUM6.4The Hide Email Address plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inline_css' parameter ...
CVE-2025-13866MEDIUM6.4The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2025-13850MEDIUM6.4The LS Google Map Router plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'map_type' parameter ...
CVE-2025-13846MEDIUM6.4The Easy Map Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in all ...
CVE-2025-13843MEDIUM6.4The VigLink SpotLight By ShortCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'float' par...
CVE-2025-13840MEDIUM6.4The BUKAZU Search widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode' parameter...
CVE-2025-13747MEDIUM6.4The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode f...
CVE-2025-13440MEDIUM5.3The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to...
CVE-2025-13408MEDIUM4.3The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to C...
CVE-2025-13366MEDIUM4.3The Rabbit Hole plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-13363MEDIUM4.3The IMAQ Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2...
CVE-2025-13334HIGH8.1The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a mi...
CVE-2025-13320MEDIUM6.8The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, ...
CVE-2025-13314MEDIUM5.3The Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus plugin for WordPress is vulnerable ...
CVE-2025-12968HIGH8.8The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now