CVE-2025-39486 is a high-severity SQL Injection vulnerability (CVSS 8.5) affecting ValvePress Rankie, allowing authenticated attackers to execute arbitrary SQL commands. The vulnerability stems from improper neutralization of special elements in SQL commands. While there is no known active exploitation, public exploit code, or significant community discussion at this time, the potential impact includes high confidentiality and low availability compromise. Organizations using ValvePress Rankie should monitor for updates and apply patches promptly once available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.8.2CPE match | cpe:2.3:a:valvepress:rankie:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.