2025 CVE Vulnerabilities
45,174 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49319 | MEDIUM | 6.5 | 0.3% | Jul 16, 2025 | Missing Authorization vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Exploiting In... |
| CVE-2025-48339 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Missing Authorization vulnerability in activity-log.com Profiler - What Slowing Down Your WP allows Exploiting Incorrect... |
| CVE-2025-30959 | MEDIUM | 6.5 | 0.3% | Jul 16, 2025 | Missing Authorization vulnerability in WPFactory Product XML Feed Manager for WooCommerce product-xml-feeds-for-woocomme... |
| CVE-2025-54051 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins LightBox ... |
| CVE-2025-54050 | MEDIUM | 5.4 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Respon... |
| CVE-2025-54047 | MEDIUM | 4.3 | 0.2% | Jul 16, 2025 | Missing Authorization vulnerability in QuanticaLabs Cost Calculator ql-cost-calculator allows Exploiting Incorrectly Con... |
| CVE-2025-54042 | MEDIUM | 4.3 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Xfinitysoft WP Post Hide wp-post-hide allows Cross Site Request Forge... |
| CVE-2025-54041 | MEDIUM | 4.3 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce... |
| CVE-2025-54039 | MEDIUM | 4.3 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Animator scroll-triggered-animations allows Cross Site ... |
| CVE-2025-54038 | MEDIUM | 5.4 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Cr... |
| CVE-2025-54037 | MEDIUM | 5.4 | 0.2% | Jul 16, 2025 | Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting... |
| CVE-2025-54036 | MEDIUM | 4.3 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Cro... |
| CVE-2025-54035 | MEDIUM | 4.3 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Newsletters newsletters-lite allows Cross Site Req... |
| CVE-2025-54033 | MEDIUM | 6.5 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in BlocksWP Theme Builder For Elementor theme-builder-for-elementor allo... |
| CVE-2025-54030 | MEDIUM | 4.3 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WesternDeal WooCommerce Google Sheet Connector wc-gsheetconnector all... |
| CVE-2025-54024 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPA... |
| CVE-2025-54023 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP De... |
| CVE-2025-54022 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Cr... |
| CVE-2025-54020 | MEDIUM | 5.4 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Erik AntiSpam for Contact Form 7 cf7-antispam allows Cross Site Reque... |
| CVE-2025-54018 | MEDIUM | 4.3 | 0.2% | Jul 16, 2025 | Missing Authorization vulnerability in CreativeMindsSolutions CM Pop-Up banners cm-pop-up-banners allows Exploiting Inco... |
| CVE-2025-54016 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Gilman Videop... |
| CVE-2025-54015 | MEDIUM | 6.6 | 0.4% | Jul 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-54013 | MEDIUM | 5.9 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welca... |
| CVE-2025-54011 | MEDIUM | 4.3 | 0.2% | Jul 16, 2025 | Missing Authorization vulnerability in SMTP2GO SMTP2GO smtp2go allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-54009 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSmar... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now