CVE-2025-39486: WordPress Rankie plugin < 1.8.2 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Rankie allows SQL Injection. This issue affects Rankie: from n/a through n/a.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Rankie valvepress-rankie allows SQL Injection.This issue affects Rankie: from n/a through < 1.8.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39486?
CVE-2025-39486 is rated as a high severity vulnerability due to its potential for SQL Injection.
How do I fix CVE-2025-39486?
To fix CVE-2025-39486, update the WordPress Rankie plugin to the latest version that addresses the SQL Injection issue.
What software is affected by CVE-2025-39486?
CVE-2025-39486 affects the WordPress Rankie plugin versions prior to 1.8.2.
What type of vulnerability is CVE-2025-39486?
CVE-2025-39486 is an SQL Injection vulnerability that results from improper neutralization of special elements in commands.
What are the risks associated with CVE-2025-39486?
The risks of CVE-2025-39486 include unauthorized access to the database, data manipulation, and exposure of sensitive information.