2025 CVE Vulnerabilities
45,207 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12216 | MEDIUM | 5.5 | 0.2% | Oct 25, 2025 | Malicious / Malformed App can be Installed but not Uninstalled/may lead to unavailability.This issue affects BLU-IC2: th... |
| CVE-2025-11897 | MEDIUM | 6.4 | 0.2% | Oct 25, 2025 | The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2025-9322 | HIGH | 7.5 | 0.3% | Oct 25, 2025 | The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress is... |
| CVE-2025-8483 | MEDIUM | 6.3 | 0.2% | Oct 25, 2025 | The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in... |
| CVE-2025-8416 | HIGH | 7.5 | 0.4% | Oct 25, 2025 | The Product Filter by WBW plugin for WordPress is vulnerable to SQL Injection via the 'filtersDataBackend' parameter in ... |
| CVE-2025-4203 | HIGH | 7.5 | 0.3% | Oct 25, 2025 | The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() fun... |
| CVE-2025-12034 | MEDIUM | 4.4 | 0.2% | Oct 25, 2025 | The Fast Velocity Minify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver... |
| CVE-2025-11976 | MEDIUM | 4.3 | 0.1% | Oct 25, 2025 | The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)... |
| CVE-2025-11893 | MEDIUM | 6.5 | 0.3% | Oct 25, 2025 | The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul... |
| CVE-2025-11875 | MEDIUM | 6.4 | 0.2% | Oct 25, 2025 | The SpendeOnline.org plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spendeonline' s... |
| CVE-2025-11497 | MEDIUM | 4.3 | 0.2% | Oct 25, 2025 | The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an... |
| CVE-2025-11255 | MEDIUM | 4.3 | 0.2% | Oct 25, 2025 | The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to unauthorized modification of data d... |
| CVE-2025-10637 | MEDIUM | 5.3 | 0.3% | Oct 25, 2025 | The Social Feed Gallery plugin for WordPress is vulnerable to Information Exposure in versions less than, or equal to, 4... |
| CVE-2025-10580 | MEDIUM | 6.4 | 0.2% | Oct 25, 2025 | The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2025-10488 | HIGH | 8.1 | 0.8% | Oct 25, 2025 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to... |
| CVE-2025-8666 | MEDIUM | 6.4 | 0.2% | Oct 25, 2025 | The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple pa... |
| CVE-2025-8588 | MEDIUM | 6.4 | 0.2% | Oct 25, 2025 | The Gutenberg Blocks – PublishPress Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Ma... |
| CVE-2025-8413 | MEDIUM | 6.4 | 0.2% | Oct 25, 2025 | The Listeo theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `soundcloud` shortcode in v... |
| CVE-2025-6680 | MEDIUM | 4.3 | 0.2% | Oct 25, 2025 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposur... |
| CVE-2025-6639 | MEDIUM | 5.4 | 0.2% | Oct 25, 2025 | The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Re... |
| CVE-2025-12095 | HIGH | 8.8 | 0.2% | Oct 25, 2025 | The Simple Registration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
| CVE-2025-12005 | MEDIUM | 4.3 | 0.2% | Oct 25, 2025 | The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to unauthorized ... |
| CVE-2025-11888 | LOW | 2.7 | 0.2% | Oct 25, 2025 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable ... |
| CVE-2025-11879 | MEDIUM | 6.5 | 0.3% | Oct 25, 2025 | The GenerateBlocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o... |
| CVE-2025-11564 | MEDIUM | 5.3 | 0.3% | Oct 25, 2025 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now