CVE-2025-39440

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 352

Summary

CVE-2025-39440 is a newly disclosed vulnerability affecting the Rajesh Broken Links Remover plugin. The issue combines Cross-Site Request Forgery (CSRF) and Stored XSS (Cross-Site Scripting) vulnerabilities, allowing attackers to inject malicious scripts into unsuspecting users' browsers. This vulnerability, present in versions 1.2.2 and older, can potentially lead to serious security consequences including data theft and unauthorized system actions. Users are strongly encouraged to upgrade to the latest, secure version of the plugin as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share