2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13969 | MEDIUM | 6.4 | 0.3% | Dec 12, 2025 | The Reviews Sorted plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'space' parameter of the [r... |
| CVE-2025-13966 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Paypal Payment Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttom_image' pa... |
| CVE-2025-13963 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The FX Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fxcc_conve... |
| CVE-2025-13962 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Divelogs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'latestdive' shor... |
| CVE-2025-13961 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Data Visualizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'visualize' short... |
| CVE-2025-13960 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The GPXpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gpxpress' shortcode in ... |
| CVE-2025-13906 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The WP Flot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linechart' shortcode in ... |
| CVE-2025-13904 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The WPGancio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gancio-event' shortcode... |
| CVE-2025-13889 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Simple Nivo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode paramete... |
| CVE-2025-13885 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Zenost Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' and 'target' para... |
| CVE-2025-13884 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Hide Email Address plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inline_css' parameter ... |
| CVE-2025-13866 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2025-13850 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The LS Google Map Router plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'map_type' parameter ... |
| CVE-2025-13846 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Easy Map Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in all ... |
| CVE-2025-13843 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The VigLink SpotLight By ShortCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'float' par... |
| CVE-2025-13840 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The BUKAZU Search widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode' parameter... |
| CVE-2025-13747 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode f... |
| CVE-2025-13440 | MEDIUM | 5.3 | 0.3% | Dec 12, 2025 | The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to... |
| CVE-2025-13408 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to C... |
| CVE-2025-13366 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Rabbit Hole plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2025-13363 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The IMAQ Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2... |
| CVE-2025-13334 | HIGH | 8.1 | 0.2% | Dec 12, 2025 | The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a mi... |
| CVE-2025-13320 | MEDIUM | 6.8 | 0.7% | Dec 12, 2025 | The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, ... |
| CVE-2025-13314 | MEDIUM | 5.3 | 0.2% | Dec 12, 2025 | The Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus plugin for WordPress is vulnerable ... |
| CVE-2025-12968 | HIGH | 8.8 | 0.5% | Dec 12, 2025 | The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now