LiveActive security incident?Get immediate response
CVE archive

January 2025

Browse CVE records published in January 2025, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 3893 matching CVEs · Page 11 of 78.

Critical · CVSS 9.3

CVE-2025-24665: WordPress Small Package Quotes Plugin <= 2.4.8 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology Small Package Quotes – Unishippers Edition small-package-quotes-unishippers-edition allows SQL Injection.This issue affects Small Package Quotes – Unishippers Edition: from n/a through <= 2.4.8.

Published Jan 27, 2025 · Updated May 11, 2026

Medium · CVSS 4.3

CVE-2025-24625: WordPress Taxonomy/Term and Role based Discounts for WooCommerce plugin <= 5.1 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability

Missing Authorization vulnerability in Marco Almeida | Webdados Taxonomy/Term and Role based Discounts for WooCommerce taxonomy-discounts-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Taxonomy/Term and Role based Discounts for WooCommerce: from n/a through <= 5.1.

Published Jan 24, 2025 · Updated May 11, 2026

Medium · CVSS 5.9

CVE-2025-24681: WordPress Product Carousel Slider & Grid Ultimate for WooCommerce Plugin <= 1.10.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Product Carousel Slider & Grid Ultimate for WooCommerce woo-product-carousel-slider-and-grid-ultimate allows Stored XSS.This issue affects Product Carousel Slider & Grid Ultimate for WooCommerce: from n/a through <= 1.10.0.

Published Jan 24, 2025 · Updated May 11, 2026