2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15041 | HIGH | 7.2 | 0.4% | Feb 19, 2026 | The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2025-14983 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The Advanced Custom Fields: Font Awesome Field plugin for WordPress is vulnerable to Cross-Site Scripting in all version... |
| CVE-2025-14864 | MEDIUM | 4.3 | 0.3% | Feb 19, 2026 | The Virusdie - One-click website security plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve... |
| CVE-2025-14851 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | The YaMaps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `yamap` shortcode par... |
| CVE-2025-14452 | HIGH | 7.2 | 0.3% | Feb 19, 2026 | The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param... |
| CVE-2025-14445 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | The Image Hotspot by DevVN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hotspot_content' c... |
| CVE-2025-14427 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | The Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to u... |
| CVE-2025-14357 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | The Mega Store Woocommerce theme for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2025-14342 | MEDIUM | 4.3 | 0.3% | Feb 19, 2026 | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ... |
| CVE-2025-14294 | MEDIUM | 5.3 | 0.4% | Feb 19, 2026 | The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2025-14270 | LOW | 2.7 | 0.3% | Feb 19, 2026 | The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, ... |
| CVE-2025-14167 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | The Remove Post Type Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-14076 | MEDIUM | 6.1 | 0.3% | Feb 19, 2026 | The iXML – Google XML sitemap generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'iX... |
| CVE-2025-13930 | MEDIUM | 5.3 | 0.4% | Feb 19, 2026 | The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass... |
| CVE-2025-13864 | MEDIUM | 5.3 | 0.4% | Feb 19, 2026 | The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up... |
| CVE-2025-13851 | CRITICAL | 9.8 | 0.3% | Feb 19, 2026 | The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user re... |
| CVE-2025-13842 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions ... |
| CVE-2025-13738 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` s... |
| CVE-2025-13732 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin... |
| CVE-2025-13617 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a13_alt_lin... |
| CVE-2025-13612 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2025-13603 | HIGH | 8.8 | 0.4% | Feb 19, 2026 | The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and i... |
| CVE-2025-13587 | MEDIUM | 6.5 | 0.4% | Feb 19, 2026 | The Two Factor (2FA) Authentication via Email plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in ... |
| CVE-2025-13563 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3... |
| CVE-2025-13438 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | The Page Title, Description & Open Graph Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now