2025 CVE Vulnerabilities

45,244 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9693HIGH8The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file del...
CVE-2025-9635MEDIUM4.3The Analytics Reduce Bounce Rate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-9634MEDIUM4.3The Plugin updates blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2025-9633MEDIUM4.3The LH Signing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2....
CVE-2025-9632MEDIUM4.3The PhpList Subber plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-9631MEDIUM4.3The AutoCatSet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2....
CVE-2025-9628MEDIUM4.3The The integration of the AMO.CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2025-9627MEDIUM4.3The Run Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1...
CVE-2025-9623MEDIUM4.3The Admin in English with Switch plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-9620MEDIUM6.1The Seo Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3...
CVE-2025-9617MEDIUM5.3The Publish approval plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2025-9451MEDIUM6.5The Smartcat Translator for WPML plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parame...
CVE-2025-9128MEDIUM6.4The eID Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up...
CVE-2025-9123MEDIUM6.4The CBX Map for Google Map & OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pop...
CVE-2025-9073HIGH7.5The All in one Minifier plugin for WordPress is vulnerable to SQL Injection via the 'post_id' parameter in all versions ...
CVE-2025-8721MEDIUM6.4The Workable Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's workable_jobs shortc...
CVE-2025-8692MEDIUM4.9The Coupon API plugin for WordPress is vulnerable to SQL Injection via the ‘log_duration’ parameter in all versions up t...
CVE-2025-8691MEDIUM6.4The WP Scriptcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter in all versi...
CVE-2025-8689MEDIUM6.4The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison, ...
CVE-2025-8686MEDIUM6.4The WP Easy FAQs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's WP_EASY_FAQ shortcod...
CVE-2025-8570CRITICAL9.8The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret managemen...
CVE-2025-8492MEDIUM5.3The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable ...
CVE-2025-8481MEDIUM4.3The Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid plugin for WordPress is vulnerable to Cross-Site...
CVE-2025-8445MEDIUM6.4The Countdown Timer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'countdown_l...
CVE-2025-8425HIGH8.8The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now