2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14465 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The Sticky Action Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-14460 | MEDIUM | 5.3 | 0.4% | Jan 7, 2026 | The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modificatio... |
| CVE-2025-14453 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The My Album Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style_css' shortcode att... |
| CVE-2025-14370 | MEDIUM | 4.3 | 0.2% | Jan 7, 2026 | The Quote Comments plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0... |
| CVE-2025-14352 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect autho... |
| CVE-2025-14147 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Easy GitHub Gist Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter... |
| CVE-2025-14145 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Niche Hero | Beautifully-designed blocks in seconds plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-14144 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Mstoic Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'start' parameter of the... |
| CVE-2025-14131 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The WP Widget Changer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']... |
| CVE-2025-14130 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Post Like Dislike plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']... |
| CVE-2025-14128 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Stumble! for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S... |
| CVE-2025-14127 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Testimonial Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF'... |
| CVE-2025-14122 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The AD Sliding FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliding_faq' shortcode in ... |
| CVE-2025-14121 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The EDD Download Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'edd_download_info_link'... |
| CVE-2025-14118 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Starred Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the PHP_SELF variable in all... |
| CVE-2025-14114 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The 1180px Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attrib... |
| CVE-2025-14113 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Viitor Button Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' shortcode ... |
| CVE-2025-14112 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The Snillrik Restaurant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'menu_style' shortcode... |
| CVE-2025-14110 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The WP Js List Pages Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortc... |
| CVE-2025-14109 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The AH Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'column' shortcode attribute... |
| CVE-2025-14077 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The Simcast plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0... |
| CVE-2025-14059 | MEDIUM | 6.5 | 0.2% | Jan 7, 2026 | The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and inc... |
| CVE-2025-14057 | MEDIUM | 4.4 | 0.3% | Jan 7, 2026 | The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver... |
| CVE-2025-14053 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Wish To Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all version... |
| CVE-2025-14028 | MEDIUM | 4.4 | 0.3% | Jan 7, 2026 | The Contact Us Simple Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now