LiveActive security incident?Get immediate response
CVE archive

April 2025

Browse CVE records published in April 2025, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 3966 matching CVEs · Page 7 of 80.

Medium · CVSS 4.3

CVE-2025-32226: WordPress Display product variations dropdown on shop page plugin <= 1.1.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Anzar Ahmed Display product variations dropdown on shop page display-product-variations-dropdown-on-shop-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display product variations dropdown on shop page: from n/a through <= 1.1.3.

Published Apr 4, 2025 · Updated May 12, 2026

Medium · CVSS 4.3

CVE-2025-32238: WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Sensitive Data Exposure vulnerability

Generation of Error Message Containing Sensitive Information vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Retrieve Embedded Sensitive Data.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.5.

Published Apr 4, 2025 · Updated May 12, 2026