Cross-Site Scripting Vulnerability in ValvePress Rankie Plugin
CVE-2025-39487
7.1HIGH
What is CVE-2025-39487?
The ValvePress Rankie plugin has a vulnerability that allows attackers to exploit reflected Cross-Site Scripting (XSS) due to improper input neutralization during web page generation. This vulnerability impacts versions from n/a through 1.8.2, enabling attackers to inject malicious scripts into web pages viewed by unsuspecting users, posing significant risks to website integrity and user safety.
Affected Version(s)
Rankie <= 1.8.2