CVE-2025-39493: WordPress Rankie plugin < 1.8.2 - Broken Access Control Vulnerability
Published May 16, 2025
·Updated
Missing Authorization vulnerability in ValvePress Rankie valvepress-rankie allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rankie: from n/a through < 1.8.2.
Affected Software
2 affected components
WordPress Rankie<=1.8.0
ValvePress Rankie Wordpress<1.8.2
Event History
May 16, 2025
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-39493?
CVE-2025-39493 is classified as a high severity vulnerability due to its missing authorization issues.
2
How do I fix CVE-2025-39493?
To fix CVE-2025-39493, update WordPress Rankie to the latest version above 1.8.0.
3
What are the potential impacts of CVE-2025-39493?
The potential impacts of CVE-2025-39493 include unauthorized access to restricted functionalities for users.
4
Which versions of Rankie are affected by CVE-2025-39493?
CVE-2025-39493 affects all versions of Rankie from n/a up to and including 1.8.0.
5
Who is the vendor of the affected software for CVE-2025-39493?
The vendor of the affected software for CVE-2025-39493 is ValvePress.