MEDIUM
CVE-2026-57651
CVSS
6.5
Description
Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions.
Summary dbcve.org
A Cross Site Scripting (XSS) vulnerability exists in the Ghost Kit WordPress plugin (versions <= 3.6.0) that allows users with Contributor-level privileges to inject malicious scripts. The vulnerability stems from insufficient input sanitization or output encoding in the plugin, potentially allowing script execution when the crafted payload is rendered in the browser.
Mitigation
Update Ghost Kit to the latest version available from the vendor, which should contain proper input sanitization and output encoding to prevent XSS attacks. If no update is available, consider removing or disabling the plugin until a patch is released.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.22%
Probability of exploitation in next 30 days
13.4th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.