2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-69341MEDIUM5.4Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-ad...
CVE-2025-69336MEDIUM4.3Missing Authorization vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Exploiting...
CVE-2025-69335MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Team S...
CVE-2025-69334MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist...
CVE-2025-69331MEDIUM4.3Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configu...
CVE-2025-69327MEDIUM4.3Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectl...
CVE-2025-63083MEDIUM6.1Lack of output escaping leads to a XSS vector in the pagebreak plugin.
CVE-2025-63082MEDIUM6.1Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
CVE-2025-46696MEDIUM6.7Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30, contain(s) an Executi...
CVE-2025-9637MEDIUM6.5The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access ...
CVE-2025-9318MEDIUM6.5The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injec...
CVE-2025-14552MEDIUM6.4The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mpp-uploader shortcode...
CVE-2025-9294MEDIUM4.3The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of...
CVE-2025-5919MEDIUM6.5The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized ...
CVE-2025-13964MEDIUM5.3The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a m...
CVE-2025-13766MEDIUM5.4The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthoriz...
CVE-2025-14371MEDIUM4.3The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized m...
CVE-2025-13812MEDIUM4.3The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ...
CVE-2025-12067MEDIUM6.4The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table C...
CVE-2025-4776MEDIUM6.4The Phlox theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption` HTML attribute in all ...
CVE-2025-13215MEDIUM5.3The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all vers...
CVE-2025-14441MEDIUM4.3The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on th...
CVE-2025-14438MEDIUM6.4The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ...
CVE-2025-14120MEDIUM6.4The URL Image Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver...
CVE-2025-14153MEDIUM6.5The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the '...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now