2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13141MEDIUM6.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2025-12039MEDIUM5.3The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versi...
CVE-2025-11973MEDIUM4.9The 简数采集器 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.6.3 via the ...
CVE-2025-11826MEDIUM6.4The WP Company Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the '...
CVE-2025-11808MEDIUM6.4The Shortcode for Google Street View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'streetvi...
CVE-2025-11803MEDIUM6.4The WPSite Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'format' shortcode attrib...
CVE-2025-13322HIGH8.1The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat...
CVE-2025-13159HIGH7.1The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG ...
CVE-2025-13142MEDIUM4.3The Custom Post Type plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2025-13135MEDIUM6.4The HotelRunner Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hotel...
CVE-2025-13134MEDIUM6.1The AuthorSure plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2....
CVE-2025-12894MEDIUM5.3The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Informa...
CVE-2025-12881MEDIUM5.4The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in...
CVE-2025-12746MEDIUM6.1The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all vers...
CVE-2025-12661MEDIUM6.4The Pollcaster Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in...
CVE-2025-12660MEDIUM6.4The Padlet Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'key' parameter in the 'w...
CVE-2025-12170MEDIUM5.3The Checkbox plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'w...
CVE-2025-12138HIGH8.8The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida...
CVE-2025-12135HIGH7.2The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versi...
CVE-2025-12086MEDIUM4.3The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in...
CVE-2025-11985HIGH8.8The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc...
CVE-2025-11885MEDIUM6.1The EchBay Admin Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_ebnonce' parame...
CVE-2025-11815MEDIUM4.3The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz...
CVE-2025-11802MEDIUM6.4The Bulma Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' shortcode attribut...
CVE-2025-11801MEDIUM6.4The AudioTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' shortcode attribute of...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now