CVE-2025-28857
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2025-28857 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Rankchecker.io Integration, from versions n/a through 1.0.9. An attacker can exploit this issue to conduct a Stored Cross-Site Scripting (XSS) attack on an unsuspecting user. This vulnerability enables the attacker to inject malicious scripts into the victim's browser, potentially stealing sensitive information or taking control of their account. The CSRF and Stored XSS weaknesses, when combined, significantly increase the risk of a successful attack. Users are strongly encouraged to update their Rankchecker.io Integration to the latest version to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress