2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14465MEDIUM4.3The Sticky Action Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-14460MEDIUM5.3The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modificatio...
CVE-2025-14453MEDIUM6.4The My Album Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style_css' shortcode att...
CVE-2025-14370MEDIUM4.3The Quote Comments plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0...
CVE-2025-14352MEDIUM5.3The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect autho...
CVE-2025-14147MEDIUM6.4The Easy GitHub Gist Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter...
CVE-2025-14145MEDIUM6.4The Niche Hero | Beautifully-designed blocks in seconds plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-14144MEDIUM6.4The Mstoic Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'start' parameter of the...
CVE-2025-14131MEDIUM6.1The WP Widget Changer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']...
CVE-2025-14130MEDIUM6.1The Post Like Dislike plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']...
CVE-2025-14128MEDIUM6.1The Stumble! for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S...
CVE-2025-14127MEDIUM6.1The Testimonial Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF'...
CVE-2025-14122MEDIUM6.4The AD Sliding FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliding_faq' shortcode in ...
CVE-2025-14121MEDIUM6.4The EDD Download Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'edd_download_info_link'...
CVE-2025-14118MEDIUM6.1The Starred Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the PHP_SELF variable in all...
CVE-2025-14114MEDIUM6.4The 1180px Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attrib...
CVE-2025-14113MEDIUM6.4The Viitor Button Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' shortcode ...
CVE-2025-14112MEDIUM6.4The Snillrik Restaurant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'menu_style' shortcode...
CVE-2025-14110MEDIUM6.4The WP Js List Pages Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortc...
CVE-2025-14109MEDIUM6.4The AH Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'column' shortcode attribute...
CVE-2025-14077MEDIUM4.3The Simcast plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0...
CVE-2025-14059MEDIUM6.5The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and inc...
CVE-2025-14057MEDIUM4.4The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver...
CVE-2025-14053MEDIUM6.4The Wish To Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all version...
CVE-2025-14028MEDIUM4.4The Contact Us Simple Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now