MEDIUM

CVE-2026-57651

2026-06-26 CVSS v3.1
CVSS
6.5

Description

Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions.

Summary dbcve.org

A Cross Site Scripting (XSS) vulnerability exists in the Ghost Kit WordPress plugin (versions <= 3.6.0) that allows users with Contributor-level privileges to inject malicious scripts. The vulnerability stems from insufficient input sanitization or output encoding in the plugin, potentially allowing script execution when the crafted payload is rendered in the browser.

Mitigation

Update Ghost Kit to the latest version available from the vendor, which should contain proper input sanitization and output encoding to prevent XSS attacks. If no update is available, consider removing or disabling the plugin until a patch is released.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.22%
Probability of exploitation in next 30 days
13.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE