2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13990MEDIUM4.3The Mamurjor Employee Info plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2025-13974MEDIUM4.4The Email Customizer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email templat...
CVE-2025-13887MEDIUM6.4The AI BotKit – AI Chatbot & Live Support for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-13849MEDIUM6.4The Cool YT Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'videoid' parameter in all ...
CVE-2025-13848MEDIUM6.4The STM Gallery 1.9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'composicion' parameter in...
CVE-2025-13847MEDIUM6.4The PhotoFade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'time' parameter in all versions...
CVE-2025-13841MEDIUM6.4The Smart App Banners plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' and 'verticalalig...
CVE-2025-13722MEDIUM5.3The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2025-13694MEDIUM5.3The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. ...
CVE-2025-13667MEDIUM6.4The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input fiel...
CVE-2025-13657MEDIUM4.3The HelpDesk contact form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-13531MEDIUM6.4The Stylish Order Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'product_name' ...
CVE-2025-13529MEDIUM5.3The Unify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t...
CVE-2025-13527MEDIUM4.3The xShare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1....
CVE-2025-13521MEDIUM4.3The WP Status Notifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2025-13520MEDIUM4.3The MTCaptcha WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2025-13519MEDIUM6.1The SVG Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-13497MEDIUM6.4The Recras WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'recrasname' shortcode at...
CVE-2025-13496MEDIUM5.3The Moosend Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2025-13419MEDIUM5.3The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to unautho...
CVE-2025-13418MEDIUM6.4The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'plan_icons' para...
CVE-2025-13369MEDIUM6.1The Premmerce WooCommerce Customers Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the...
CVE-2025-12648MEDIUM5.3The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and includin...
CVE-2025-12540MEDIUM4.7The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
CVE-2025-12449MEDIUM5.4The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and dis...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now