2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14077 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The Simcast plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0... |
| CVE-2025-14059 | MEDIUM | 6.5 | 0.2% | Jan 7, 2026 | The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and inc... |
| CVE-2025-14057 | MEDIUM | 4.4 | 0.3% | Jan 7, 2026 | The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver... |
| CVE-2025-14053 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Wish To Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all version... |
| CVE-2025-14028 | MEDIUM | 4.4 | 0.3% | Jan 7, 2026 | The Contact Us Simple Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v... |
| CVE-2025-13990 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The Mamurjor Employee Info plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-13974 | MEDIUM | 4.4 | 0.3% | Jan 7, 2026 | The Email Customizer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email templat... |
| CVE-2025-13887 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The AI BotKit – AI Chatbot & Live Support for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-13849 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Cool YT Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'videoid' parameter in all ... |
| CVE-2025-13848 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The STM Gallery 1.9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'composicion' parameter in... |
| CVE-2025-13847 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The PhotoFade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'time' parameter in all versions... |
| CVE-2025-13841 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Smart App Banners plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' and 'verticalalig... |
| CVE-2025-13722 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2025-13694 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. ... |
| CVE-2025-13667 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input fiel... |
| CVE-2025-13657 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The HelpDesk contact form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-13531 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Stylish Order Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'product_name' ... |
| CVE-2025-13529 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The Unify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t... |
| CVE-2025-13527 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The xShare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1.... |
| CVE-2025-13521 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The WP Status Notifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2025-13520 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The MTCaptcha WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2025-13519 | MEDIUM | 6.1 | 0.1% | Jan 7, 2026 | The SVG Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-13497 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Recras WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'recrasname' shortcode at... |
| CVE-2025-13496 | MEDIUM | 5.3 | 0.3% | Jan 7, 2026 | The Moosend Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2025-13419 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to unautho... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now