2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12663MEDIUM6.4The Jeba Cute forkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter in the '...
CVE-2025-12662MEDIUM6.4The Coon Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in the...
CVE-2025-12658MEDIUM6.4The Preload Current Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'complete' paramete...
CVE-2025-12652MEDIUM6.4The Ungapped Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prefillvalues' parameter...
CVE-2025-12651MEDIUM6.4The Live Photos on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_src', 'img...
CVE-2025-12644MEDIUM6.4The Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2025-12637HIGH8.8The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation f...
CVE-2025-12632MEDIUM5.5The RandomQuotr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2025-12631MEDIUM4.4The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all...
CVE-2025-12590MEDIUM6.1The YSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versi...
CVE-2025-12589MEDIUM6.1The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all vers...
CVE-2025-12588MEDIUM4.3The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2025-12538MEDIUM4.4The Fleet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u...
CVE-2025-12526MEDIUM4.3The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2025-12132MEDIUM4.3The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ...
CVE-2025-12126MEDIUM5.4The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,...
CVE-2025-12021MEDIUM6.1The WP-OAuth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error_description' parameter ...
CVE-2025-12020MEDIUM4.9The Double the Donation – A workplace giving tool to help your fundraising efforts plugin for WordPress is vulnerable to...
CVE-2025-12019MEDIUM5.5The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image metadata in all versions ...
CVE-2025-12010MEDIUM6.5The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2025-11999MEDIUM5.3The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capa...
CVE-2025-11997MEDIUM5.3The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure i...
CVE-2025-11996MEDIUM5.3The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check...
CVE-2025-11988MEDIUM5.3The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including,...
CVE-2025-11986MEDIUM5.3The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now