CVE-2025-39440
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-39440 is a newly disclosed vulnerability affecting the Rajesh Broken Links Remover plugin. The issue combines Cross-Site Request Forgery (CSRF) and Stored XSS (Cross-Site Scripting) vulnerabilities, allowing attackers to inject malicious scripts into unsuspecting users' browsers. This vulnerability, present in versions 1.2.2 and older, can potentially lead to serious security consequences including data theft and unauthorized system actions. Users are strongly encouraged to upgrade to the latest, secure version of the plugin as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress