2025 CVE Vulnerabilities
45,244 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9693 | HIGH | 8 | 0.5% | Sep 11, 2025 | The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file del... |
| CVE-2025-9635 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The Analytics Reduce Bounce Rate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-9634 | MEDIUM | 4.3 | 0.1% | Sep 11, 2025 | The Plugin updates blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-9633 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The LH Signing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.... |
| CVE-2025-9632 | MEDIUM | 4.3 | 0.1% | Sep 11, 2025 | The PhpList Subber plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-9631 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The AutoCatSet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.... |
| CVE-2025-9628 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The The integration of the AMO.CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2025-9627 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The Run Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1... |
| CVE-2025-9623 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The Admin in English with Switch plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-9620 | MEDIUM | 6.1 | 0.1% | Sep 11, 2025 | The Seo Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3... |
| CVE-2025-9617 | MEDIUM | 5.3 | 0.1% | Sep 11, 2025 | The Publish approval plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2025-9451 | MEDIUM | 6.5 | 0.3% | Sep 11, 2025 | The Smartcat Translator for WPML plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parame... |
| CVE-2025-9128 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The eID Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up... |
| CVE-2025-9123 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The CBX Map for Google Map & OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pop... |
| CVE-2025-9073 | HIGH | 7.5 | 0.4% | Sep 11, 2025 | The All in one Minifier plugin for WordPress is vulnerable to SQL Injection via the 'post_id' parameter in all versions ... |
| CVE-2025-8721 | MEDIUM | 6.4 | 0.3% | Sep 11, 2025 | The Workable Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's workable_jobs shortc... |
| CVE-2025-8692 | MEDIUM | 4.9 | 0.4% | Sep 11, 2025 | The Coupon API plugin for WordPress is vulnerable to SQL Injection via the ‘log_duration’ parameter in all versions up t... |
| CVE-2025-8691 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The WP Scriptcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter in all versi... |
| CVE-2025-8689 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison, ... |
| CVE-2025-8686 | MEDIUM | 6.4 | 0.3% | Sep 11, 2025 | The WP Easy FAQs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's WP_EASY_FAQ shortcod... |
| CVE-2025-8570 | CRITICAL | 9.8 | 0.6% | Sep 11, 2025 | The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret managemen... |
| CVE-2025-8492 | MEDIUM | 5.3 | 0.3% | Sep 11, 2025 | The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable ... |
| CVE-2025-8481 | MEDIUM | 4.3 | 0.1% | Sep 11, 2025 | The Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid plugin for WordPress is vulnerable to Cross-Site... |
| CVE-2025-8445 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Countdown Timer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'countdown_l... |
| CVE-2025-8425 | HIGH | 8.8 | 0.3% | Sep 11, 2025 | The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now