2025 CVE Vulnerabilities

45,207 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12216MEDIUM5.5Malicious / Malformed App can be Installed but not Uninstalled/may lead to unavailability.This issue affects BLU-IC2: th...
CVE-2025-11897MEDIUM6.4The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2025-9322HIGH7.5The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress is...
CVE-2025-8483MEDIUM6.3The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in...
CVE-2025-8416HIGH7.5The Product Filter by WBW plugin for WordPress is vulnerable to SQL Injection via the 'filtersDataBackend' parameter in ...
CVE-2025-4203HIGH7.5The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() fun...
CVE-2025-12034MEDIUM4.4The Fast Velocity Minify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver...
CVE-2025-11976MEDIUM4.3The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)...
CVE-2025-11893MEDIUM6.5The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul...
CVE-2025-11875MEDIUM6.4The SpendeOnline.org plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spendeonline' s...
CVE-2025-11497MEDIUM4.3The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2025-11255MEDIUM4.3The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2025-10637MEDIUM5.3The Social Feed Gallery plugin for WordPress is vulnerable to Information Exposure in versions less than, or equal to, 4...
CVE-2025-10580MEDIUM6.4The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2025-10488HIGH8.1The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to...
CVE-2025-8666MEDIUM6.4The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple pa...
CVE-2025-8588MEDIUM6.4The Gutenberg Blocks – PublishPress Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Ma...
CVE-2025-8413MEDIUM6.4The Listeo theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `soundcloud` shortcode in v...
CVE-2025-6680MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposur...
CVE-2025-6639MEDIUM5.4The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Re...
CVE-2025-12095HIGH8.8The Simple Registration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2025-12005MEDIUM4.3The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to unauthorized ...
CVE-2025-11888LOW2.7The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable ...
CVE-2025-11879MEDIUM6.5The GenerateBlocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o...
CVE-2025-11564MEDIUM5.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now