CVE-2025-39487: WordPress Rankie plugin <= 1.8.2 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Rankie allows Reflected XSS. This issue affects Rankie: from n/a through 1.8.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Rankie valvepress-rankie allows Reflected XSS.This issue affects Rankie: from n/a through <= 1.8.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39487?
CVE-2025-39487 is categorized as a Reflected Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2025-39487?
To fix CVE-2025-39487, upgrade ValvePress Rankie to version 1.8.3 or later.
What versions of ValvePress Rankie are affected by CVE-2025-39487?
CVE-2025-39487 affects ValvePress Rankie from all versions up to and including 1.8.2.
What is Cross-site Scripting in the context of CVE-2025-39487?
Cross-site Scripting (XSS) in the context of CVE-2025-39487 refers to the ability for an attacker to inject malicious scripts into web pages viewed by users.
Where can I find more information about CVE-2025-39487?
More information about CVE-2025-39487 can typically be found in security advisories or vulnerability databases.