Junglewise Threat Intelligence

CVE-2026-57656: Peregrine Themes Hester Core XSS in WordPress plugin

CVE-2026-57656 · Severity: medium · CVSS 5.9 · Published 2026-06-26

Executive brief

Hester Core is a WordPress plugin used to provide core functionality for specific website themes. A security vulnerability in versions 1.1.8 and earlier allows users with 'Author' level permissions to inject malicious scripts into the website. If a site administrator views the affected content, these scripts could be used to redirect visitors to malicious sites, display unauthorized advertisements, or potentially compromise the website's integrity.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Hester Core plugin for WordPress (versions <= 1.1.8) due to improper neutralization of input during web page generation (CWE-79). The vulnerability requires 'Author' level privileges (PR:H) and some degree of user interaction (UI:R) from a victim, such as an administrator viewing the malicious content. Successful exploitation allows an attacker to inject arbitrary HTML or JavaScript payloads that execute in the context of other users' browsers. The issue is addressed in version 1.1.9.

Affected products

  • peregrinethemes Hester Core <= 1.1.8

Timeline

  • 2026-06-12: other: Reported by researcher Ananda Dhakal
  • 2026-06-26: advisory: Published by Patchstack and NVD
  • 2026-06-26: patched: Version 1.1.9 released to address the vulnerability

References