2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15041HIGH7.2The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2025-14983MEDIUM6.4The Advanced Custom Fields: Font Awesome Field plugin for WordPress is vulnerable to Cross-Site Scripting in all version...
CVE-2025-14864MEDIUM4.3The Virusdie - One-click website security plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve...
CVE-2025-14851MEDIUM6.4The YaMaps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `yamap` shortcode par...
CVE-2025-14452HIGH7.2The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param...
CVE-2025-14445MEDIUM6.4The Image Hotspot by DevVN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hotspot_content' c...
CVE-2025-14427MEDIUM4.3The Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to u...
CVE-2025-14357MEDIUM5.3The Mega Store Woocommerce theme for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2025-14342MEDIUM4.3The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2025-14294MEDIUM5.3The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2025-14270LOW2.7The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, ...
CVE-2025-14167MEDIUM4.3The Remove Post Type Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-14076MEDIUM6.1The iXML – Google XML sitemap generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'iX...
CVE-2025-13930MEDIUM5.3The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass...
CVE-2025-13864MEDIUM5.3The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up...
CVE-2025-13851CRITICAL9.8The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user re...
CVE-2025-13842MEDIUM5.3The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions ...
CVE-2025-13738MEDIUM6.4The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` s...
CVE-2025-13732MEDIUM6.4The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin...
CVE-2025-13617MEDIUM6.4The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a13_alt_lin...
CVE-2025-13612MEDIUM6.4The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2025-13603HIGH8.8The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and i...
CVE-2025-13587MEDIUM6.5The Two Factor (2FA) Authentication via Email plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in ...
CVE-2025-13563CRITICAL9.8The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3...
CVE-2025-13438MEDIUM4.3The Page Title, Description & Open Graph Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now