2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13413MEDIUM4.3The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ...
CVE-2025-13113MEDIUM5.3The Web Accessibility by accessiBe plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2025-13091MEDIUM4.3The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on ...
CVE-2025-13079MEDIUM5.3The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to au...
CVE-2025-13048MEDIUM6.4The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-12975HIGH7.2The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin inst...
CVE-2025-12884MEDIUM4.3The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to authorization bypass in versions up to, an...
CVE-2025-12882CRITICAL9.8The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. ...
CVE-2025-12845HIGH8.8The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to ...
CVE-2025-12821HIGH8.8The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is...
CVE-2025-12707HIGH7.5The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all version...
CVE-2025-12500MEDIUM5.3The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limi...
CVE-2025-12451MEDIUM4.4The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versi...
CVE-2025-12448MEDIUM6.4The Smartsupp – live chat, AI shopping assistant and chatbots plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2025-12375MEDIUM6.4The Printful Integration for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio...
CVE-2025-12172MEDIUM4.3The Mailchimp List Subscribe Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2025-12117MEDIUM6.4The Renden theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, an...
CVE-2025-12116MEDIUM6.4The Drift theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and...
CVE-2025-12081MEDIUM4.3The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2025-12027MEDIUM4.3The Mesmerize Companion plugin for WordPress is vulnerable to unauthorized access and modification of data due to a miss...
CVE-2025-11754HIGH7.5The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch...
CVE-2025-11725MEDIUM6.5The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil...
CVE-2025-11706MEDIUM6.1The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the dbstatus parameter ...
CVE-2025-15585MEDIUM6.7Fileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file searc...
CVE-2025-15581MEDIUM4.7Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authenticati...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now