Junglewise Threat Intelligence

CVE-2026-39683: Chief Gnome Garden Gnome Package DOM-based XSS

CVE-2026-39683 · Severity: medium · CVSS 5.9 · Published 2026-04-08

Executive brief

The Garden Gnome Package plugin for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. An attacker with high-level privileges, such as an Author, could use this to redirect visitors to malicious sites or steal sensitive information from other users. This risk is mitigated by the fact that it requires a specific action from a victim, such as clicking a link, and requires the attacker to already have significant access to the site.

Technical details

A DOM-based cross-site scripting (XSS) vulnerability exists in the Chief Gnome Garden Gnome Package plugin for WordPress due to improper neutralization of input during web page generation. The flaw allows an attacker with 'Author' or higher privileges to inject malicious scripts that execute in the context of a victim's browser. Exploitation requires network access and user interaction, such as a privileged user visiting a specially crafted page. The vulnerability is present in versions up to and including 2.5.1 and is addressed in version 2.5.2.

Affected products

  • Chief Gnome Garden Gnome Package <= 2.5.1

Timeline

  • 2026-01-22: other: Reported by Nabil Irawan
  • 2026-02-21: advisory: Patchstack published advisory
  • 2026-04-08: disclosed: CVE published

References