2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10682 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. This is due to ... |
| CVE-2025-10660 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, ... |
| CVE-2025-10648 | MEDIUM | 5.3 | 0.3% | Oct 15, 2025 | The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due t... |
| CVE-2025-10575 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The WP jQuery Pager plugin for WordPress is vulnerable to SQL Injection via the 'ids' shortcode attribute parameter hand... |
| CVE-2025-10486 | MEDIUM | 5.3 | 0.3% | Oct 15, 2025 | The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu... |
| CVE-2025-10313 | HIGH | 7.2 | 0.3% | Oct 15, 2025 | The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scriptin... |
| CVE-2025-10312 | MEDIUM | 4.3 | 0.1% | Oct 15, 2025 | The Theme Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-10310 | MEDIUM | 4.9 | 0.3% | Oct 15, 2025 | The Rich Snippet Site Report plugin for WordPress is vulnerable to SQL Injection via the 'last' parameter in all versio... |
| CVE-2025-10303 | MEDIUM | 4.3 | 0.2% | Oct 15, 2025 | The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2025-10301 | MEDIUM | 4.3 | 0.1% | Oct 15, 2025 | The FunKItools plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.... |
| CVE-2025-10300 | MEDIUM | 4.3 | 0.2% | Oct 15, 2025 | The TopBar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0.... |
| CVE-2025-10299 | HIGH | 8.8 | 0.3% | Oct 15, 2025 | The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress is vulnerable to Privilege Escalation du... |
| CVE-2025-10294 | CRITICAL | 9.8 | 0.8% | Oct 15, 2025 | The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and incl... |
| CVE-2025-10293 | HIGH | 8.8 | 0.3% | Oct 15, 2025 | The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account ta... |
| CVE-2025-10194 | MEDIUM | 6.4 | 0.3% | Oct 15, 2025 | The Shortcode Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortco... |
| CVE-2025-10186 | MEDIUM | 5.3 | 0.3% | Oct 15, 2025 | The WhyDonate – FREE Donate button – Crowdfunding – Fundraising plugin for WordPress is vulnerable to unauthorized loss ... |
| CVE-2025-10141 | MEDIUM | 6.4 | 0.3% | Oct 15, 2025 | The Digiseller plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ds' shortcode in all ... |
| CVE-2025-10140 | MEDIUM | 6.4 | 0.3% | Oct 15, 2025 | The Quick Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quick-login' ... |
| CVE-2025-10139 | MEDIUM | 6.4 | 0.3% | Oct 15, 2025 | The WP BookWidgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bw_link' shortcod... |
| CVE-2025-10135 | MEDIUM | 6.4 | 0.2% | Oct 15, 2025 | The WP ViewSTL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewstl' shortcode in... |
| CVE-2025-10133 | MEDIUM | 6.4 | 0.2% | Oct 15, 2025 | The URLYar URL Shortner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'urlyar_short... |
| CVE-2025-10132 | MEDIUM | 6.4 | 0.2% | Oct 15, 2025 | The Dhivehi Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dhivehi' shortcode ... |
| CVE-2025-10056 | MEDIUM | 4.4 | 0.2% | Oct 15, 2025 | The Task Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin... |
| CVE-2025-10051 | HIGH | 7.2 | 0.6% | Oct 15, 2025 | The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ... |
| CVE-2025-10045 | MEDIUM | 4.9 | 0.3% | Oct 15, 2025 | The onOffice for WP-Websites plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now