2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13620MEDIUM5.3The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions ...
CVE-2025-13739MEDIUM6.4The CryptX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `cryptx` shortcode in all ...
CVE-2025-13682MEDIUM4.4The Trail Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u...
CVE-2025-13678MEDIUM6.4The Thai Lottery Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `thailottery` shortcod...
CVE-2025-13614HIGH8.1The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' s...
CVE-2025-12879HIGH8.8The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and i...
CVE-2025-12876MEDIUM5.3The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2025-12851HIGH8.1The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,...
CVE-2025-13684MEDIUM4.3The ARK Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.19. This is due to m...
CVE-2025-12130MEDIUM4.3The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to...
CVE-2025-13515MEDIUM6.1The Nouri.sh Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF...
CVE-2025-12850HIGH7.5The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versio...
CVE-2025-12374CRITICAL9.8The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plu...
CVE-2025-12373MEDIUM4.3The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to Cross...
CVE-2025-12355MEDIUM5.3The Payaza plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on ...
CVE-2025-12354MEDIUM4.3The Live CSS Preview plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2025-12186MEDIUM4.4The Weekly Planner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions ...
CVE-2025-12093MEDIUM5.3The Voidek Employee Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o...
CVE-2025-66270MEDIUM4.7The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect ...
CVE-2025-32900MEDIUM4.3In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the di...
CVE-2025-13860MEDIUM6.4The Easy Jump Links Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `h_tags` parameter i...
CVE-2025-13625MEDIUM6.1The WP-SOS-Donate Donation Sidebar Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVE...
CVE-2025-13623MEDIUM6.1The Twitscription plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in al...
CVE-2025-13622MEDIUM6.1The Jabbernotification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO ...
CVE-2025-13621MEDIUM6.1The dream gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now