2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10682MEDIUM6.5The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. This is due to ...
CVE-2025-10660MEDIUM6.5The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, ...
CVE-2025-10648MEDIUM5.3The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due t...
CVE-2025-10575MEDIUM6.5The WP jQuery Pager plugin for WordPress is vulnerable to SQL Injection via the 'ids' shortcode attribute parameter hand...
CVE-2025-10486MEDIUM5.3The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu...
CVE-2025-10313HIGH7.2The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scriptin...
CVE-2025-10312MEDIUM4.3The Theme Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-10310MEDIUM4.9The Rich Snippet Site Report plugin for WordPress is vulnerable to SQL Injection via the 'last' parameter in all versio...
CVE-2025-10303MEDIUM4.3The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2025-10301MEDIUM4.3The FunKItools plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2025-10300MEDIUM4.3The TopBar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0....
CVE-2025-10299HIGH8.8The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress is vulnerable to Privilege Escalation du...
CVE-2025-10294CRITICAL9.8The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and incl...
CVE-2025-10293HIGH8.8The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account ta...
CVE-2025-10194MEDIUM6.4The Shortcode Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortco...
CVE-2025-10186MEDIUM5.3The WhyDonate – FREE Donate button – Crowdfunding – Fundraising plugin for WordPress is vulnerable to unauthorized loss ...
CVE-2025-10141MEDIUM6.4The Digiseller plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ds' shortcode in all ...
CVE-2025-10140MEDIUM6.4The Quick Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quick-login' ...
CVE-2025-10139MEDIUM6.4The WP BookWidgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bw_link' shortcod...
CVE-2025-10135MEDIUM6.4The WP ViewSTL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewstl' shortcode in...
CVE-2025-10133MEDIUM6.4The URLYar URL Shortner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'urlyar_short...
CVE-2025-10132MEDIUM6.4The Dhivehi Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dhivehi' shortcode ...
CVE-2025-10056MEDIUM4.4The Task Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin...
CVE-2025-10051HIGH7.2The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ...
CVE-2025-10045MEDIUM4.9The onOffice for WP-Websites plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now