2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13990 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The Mamurjor Employee Info plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-13974 | MEDIUM | 4.4 | 0.3% | Jan 7, 2026 | The Email Customizer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email templat... |
| CVE-2025-13887 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The AI BotKit – AI Chatbot & Live Support for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-13849 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Cool YT Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'videoid' parameter in all ... |
| CVE-2025-13848 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The STM Gallery 1.9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'composicion' parameter in... |
| CVE-2025-13847 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The PhotoFade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'time' parameter in all versions... |
| CVE-2025-13841 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Smart App Banners plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' and 'verticalalig... |
| CVE-2025-13722 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2025-13694 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. ... |
| CVE-2025-13667 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input fiel... |
| CVE-2025-13657 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The HelpDesk contact form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-13531 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Stylish Order Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'product_name' ... |
| CVE-2025-13529 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The Unify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t... |
| CVE-2025-13527 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The xShare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1.... |
| CVE-2025-13521 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The WP Status Notifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2025-13520 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The MTCaptcha WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2025-13519 | MEDIUM | 6.1 | 0.1% | Jan 7, 2026 | The SVG Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-13497 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Recras WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'recrasname' shortcode at... |
| CVE-2025-13496 | MEDIUM | 5.3 | 0.3% | Jan 7, 2026 | The Moosend Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2025-13419 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to unautho... |
| CVE-2025-13418 | MEDIUM | 6.4 | 0.6% | Jan 7, 2026 | The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'plan_icons' para... |
| CVE-2025-13369 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Premmerce WooCommerce Customers Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the... |
| CVE-2025-12648 | MEDIUM | 5.3 | 0.3% | Jan 7, 2026 | The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and includin... |
| CVE-2025-12540 | MEDIUM | 4.7 | 0.2% | Jan 7, 2026 | The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Sensitive Information Exposure in all... |
| CVE-2025-12449 | MEDIUM | 5.4 | 0.3% | Jan 7, 2026 | The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and dis... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now