2025 CVE Vulnerabilities

45,227 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9858MEDIUM6.4The Auto Bulb Finder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'a...
CVE-2025-9854MEDIUM6.4The A Simple Multilanguage Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'as...
CVE-2025-9630MEDIUM4.3The WP SinoType plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-9561HIGH8.8The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insuffic...
CVE-2025-9372MEDIUM5.5The Ultimate Multi Design Video Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versio...
CVE-2025-9333MEDIUM5.5The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t...
CVE-2025-9332MEDIUM5.5The Interactive Human Anatomy with Clickable Body Parts plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-9286CRITICAL9.8The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authoriza...
CVE-2025-9213HIGH8.8The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due...
CVE-2025-9212HIGH7.5The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-9209CRITICAL9.8The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3....
CVE-2025-9206MEDIUM6.4The Meks Easy Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title field in all ver...
CVE-2025-9204MEDIUM6.4The X Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Youtube Video ID fi...
CVE-2025-9200HIGH7.5The Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App plugin for WordPress is vulnerable to SQ...
CVE-2025-9199MEDIUM6.5The Woo superb slideshow transition gallery with random effect plugin for WordPress is vulnerable to SQL Injection via t...
CVE-2025-9198MEDIUM6.5The Wp cycle text announcement plugin for WordPress is vulnerable to SQL Injection via the 'cycle-text' shortcode in all...
CVE-2025-9194MEDIUM4.3The Constructor theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2025-9130MEDIUM6.4The Unify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's unify_checkou...
CVE-2025-9129MEDIUM6.4The Flexi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's flexi-form-ta...
CVE-2025-9080MEDIUM6.4The Generic Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget fields in ver...
CVE-2025-9077MEDIUM6.4The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Animated ...
CVE-2025-9045MEDIUM6.4The Easy Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameter...
CVE-2025-8776MEDIUM6.4The Epic Bootstrap Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icol’ parameter in...
CVE-2025-8669MEDIUM4.3The Customify theme for WordPress is vulnerable to Cross-Site Request Forgery in version 0.4.11. This is due to missing ...
CVE-2025-7825MEDIUM6.3The Schema Plugin For Divi, Gutenberg & Shortcodes plugin for WordPress is vulnerable to Object Instantiation in all ver...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now