CVE-2025-39528
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 16, 2025
CWE ID 79
Summary
CVE-2025-39528 is a Cross-Site Scripting (XSS) vulnerability affecting Rescue Shortcodes, a plugin used in Rescue Themes. The flaw, which allows Stored XSS, occurs during the generation of web pages. Attackers can exploit this issue by injecting malicious scripts into vulnerable websites, potentially stealing user data or taking control of user sessions. Affected versions of Rescue Shortcodes range from the unspecified "n/a" through 3.1. Users are strongly advised to update to the latest version or consider alternative solutions to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Rescue Shortcodes Plugin
Affected Vendors
- WordPress