CVE-2025-62059: WordPress SureRank plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability
Published Nov 6, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force SureRank surerank.This issue affects SureRank: from n/a through <= 1.3.2.
Affected Software
2 affected components
Brainstorm Force SureRank<=1.3.2
WordPress SureRank plugin<=1.3.2
Event History
Nov 6, 2025
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62059?
CVE-2025-62059 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2025-62059?
To fix CVE-2025-62059, update the SureRank plugin to version 1.3.3 or later.
3
What versions of SureRank are affected by CVE-2025-62059?
CVE-2025-62059 affects SureRank versions from n/a through 1.3.2.
4
What is the nature of the vulnerability described in CVE-2025-62059?
CVE-2025-62059 is an improper neutralization of input during web page generation, leading to a cross-site scripting vulnerability.
5
Who is the vendor associated with CVE-2025-62059?
The vendor associated with CVE-2025-62059 is Brainstorm Force.