2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13563CRITICAL9.8The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3...
CVE-2025-13438MEDIUM4.3The Page Title, Description & Open Graph Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2025-13413MEDIUM4.3The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ...
CVE-2025-13113MEDIUM5.3The Web Accessibility by accessiBe plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2025-13091MEDIUM4.3The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on ...
CVE-2025-13079MEDIUM5.3The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to au...
CVE-2025-13048MEDIUM6.4The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-12975HIGH7.2The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin inst...
CVE-2025-12884MEDIUM4.3The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to authorization bypass in versions up to, an...
CVE-2025-12882CRITICAL9.8The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. ...
CVE-2025-12845HIGH8.8The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to ...
CVE-2025-12821HIGH8.8The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.5.9. This is...
CVE-2025-12707HIGH7.5The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all version...
CVE-2025-12500MEDIUM5.3The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limi...
CVE-2025-12451MEDIUM4.4The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versi...
CVE-2025-12448MEDIUM6.4The Smartsupp – live chat, AI shopping assistant and chatbots plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2025-12375MEDIUM6.4The Printful Integration for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio...
CVE-2025-12172MEDIUM4.3The Mailchimp List Subscribe Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2025-12117MEDIUM6.4The Renden theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, an...
CVE-2025-12116MEDIUM6.4The Drift theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and...
CVE-2025-12081MEDIUM4.3The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2025-12027MEDIUM4.3The Mesmerize Companion plugin for WordPress is vulnerable to unauthorized access and modification of data due to a miss...
CVE-2025-11754HIGH7.5The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch...
CVE-2025-11725MEDIUM6.5The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil...
CVE-2025-11706MEDIUM6.1The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the dbstatus parameter ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now