Junglewise Threat Intelligence

CVE-2026-57651: nK Ghost Kit Contributor XSS in WordPress plugin

CVE-2026-57651 · Severity: medium · CVSS 6.5 · Published 2026-06-26

Executive brief

Ghost Kit is a WordPress plugin that provides advanced blocks and tools for the Gutenberg editor. A security vulnerability allows users with 'Contributor' level access to inject malicious scripts into website pages. If a site administrator or visitor views the affected content, these scripts could execute, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the nK Ghost Kit plugin for WordPress (versions <= 3.6.0) due to improper neutralization of input during web page generation (CWE-79). The flaw allows authenticated attackers with 'Contributor' level privileges to inject arbitrary JavaScript into the site. Exploitation requires a victim (such as an administrator) to interact with or view the malicious content. Successful exploitation can lead to session hijacking, unauthorized administrative actions, or website defacement. The issue is resolved in version 3.6.1.

Affected products

  • nK Ghost Kit <= 3.6.0

Timeline

  • 2026-06-12: other: Reported by researcher Ananda Dhakal
  • 2026-06-26: disclosed: Published by Patchstack
  • 2026-06-26: patched: Fixed in version 3.6.1

References