CVE-2026-57651
Deferred Deferred - Pending Action
Ghost Kit Plugin Cross Site Scripting (XSS)

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: Patchstack

Description
Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
patchstack ghost_kit to 3.6.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The WordPress Ghost Kit Plugin versions 3.6.0 and below have a Cross Site Scripting (XSS) vulnerability. This means that attackers can inject malicious scripts into the website, which then execute when visitors access the site.

Exploitation requires a privileged user to perform an action such as clicking a malicious link or submitting a form, allowing the attacker to insert harmful scripts like redirects or advertisements.

This vulnerability has been fixed in version 3.6.1 of the plugin.

Impact Analysis

If exploited, this vulnerability can allow attackers to inject harmful scripts into your website, which may execute unwanted redirects, display malicious advertisements, or perform other malicious actions.

Such attacks could affect the integrity and user experience of your website and potentially harm your visitors.

The risk is considered moderate with a CVSS score of 6.5, and attackers could exploit it in mass campaigns targeting many websites.

Detection Guidance

The vulnerability affects WordPress sites using the Ghost Kit Plugin version 3.6.0 or below. Detection involves identifying if this plugin and vulnerable version are installed.

  • Check the installed Ghost Kit plugin version in your WordPress installation.
  • Look for suspicious script injections or unexpected redirects on your website that could indicate exploitation.

Specific commands are not provided in the available resources.

Mitigation Strategies

To mitigate this vulnerability, immediately update the Ghost Kit plugin to version 3.6.1 or later, where the issue has been patched.

If you use Patchstack, enable auto-updates for vulnerable plugins to ensure timely patching.

Be cautious with privileged users performing actions such as clicking links or submitting forms, as exploitation requires such user interaction.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57651. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart