Skip to main content

CVE-2025-9992: Ghost Kit WordPress Plugin XSS Vulnerability

CVE-2025-9992 is a stored cross-site scripting flaw in Ghost Kit WordPress plugin that allows authenticated attackers to inject malicious scripts. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2025-9992 Overview

CVE-2025-9992 is a stored Cross-Site Scripting (XSS) vulnerability [CWE-79] in the Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress. The flaw affects all versions up to and including 3.4.3. The vulnerability resides in the plugin's custom JS field, which lacks sufficient input sanitization and output escaping. Authenticated attackers with Contributor-level access or higher can inject arbitrary JavaScript into pages. The injected scripts execute whenever a user visits an affected page, enabling session theft, redirection, or drive-by actions performed in the victim's browser context.

Critical Impact

Authenticated Contributors can persist arbitrary JavaScript that executes for any visitor to affected pages, enabling account takeover of higher-privileged users.

Affected Products

  • Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress
  • All versions up to and including 3.4.3
  • WordPress sites permitting Contributor-level or higher registration

Discovery Timeline

  • 2025-09-18 - CVE-2025-9992 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-9992

Vulnerability Analysis

The Ghost Kit plugin exposes a custom JS field within its Gutenberg custom-code component. The plugin accepts user-supplied JavaScript intended for inclusion in rendered pages but fails to enforce capability checks and output escaping proportional to the sensitivity of the operation. As a result, users at the Contributor role, who normally cannot publish executable scripts, can persist arbitrary JavaScript that later executes in the browser of any visitor, including administrators. This turns a low-privileged content role into a vector for stealing session cookies, hijacking authenticated sessions, or forging administrative actions through the DOM.

Root Cause

The root cause is insufficient input sanitization and output escaping in the plugin's custom-code handler at gutenberg/plugins/custom-code/index.php. The plugin persists custom JavaScript supplied through the block editor without stripping executable payloads and without restricting the capability required to save it. The fix landed in changeset 3359701 in the plugin's WordPress.org repository.

Attack Vector

Exploitation requires an authenticated account with Contributor-level access or higher. The attacker edits a post or page and injects JavaScript through the Ghost Kit custom JS field. Once the content is rendered, any user who loads the page executes the attacker's payload in their own browser session. Because the scope is changed (S:C in the CVSS vector), impact can extend beyond the plugin to the WordPress site as a whole, including administrator sessions.

No public proof-of-concept exploit code is referenced in the advisory. For technical details on the code change, see the WordPress Custom Code Change and the Wordfence Vulnerability Analysis.

Detection Methods for CVE-2025-9992

Indicators of Compromise

  • Ghost Kit blocks containing <script> tags, event handlers such as onerror= or onload=, or references to external JavaScript sources authored by Contributor-role accounts.
  • Unexpected outbound requests from visitor browsers to attacker-controlled domains originating on pages that use Ghost Kit custom code.
  • New or recently modified posts by low-privileged users that render inline JavaScript.

Detection Strategies

  • Review the wp_posts table for post content containing Ghost Kit custom-code blocks with JavaScript payloads, filtered by post_author mapped to Contributor accounts.
  • Compare the installed plugin version against 3.4.3 and flag any WordPress instance running an affected build.
  • Inspect page HTML in staging environments for scripts that reference third-party domains not associated with legitimate site functionality.

Monitoring Recommendations

  • Alert on privilege changes and new Contributor account creation on WordPress sites that permit registration.
  • Monitor web server access logs for suspicious query patterns following page loads, such as beacons or credential exfiltration attempts.
  • Track plugin update events in WordPress audit logs to confirm Ghost Kit has been updated site-wide.

How to Mitigate CVE-2025-9992

Immediate Actions Required

  • Update the Ghost Kit plugin to a version later than 3.4.3 on all WordPress sites.
  • Audit posts and pages authored by Contributor-role accounts for embedded JavaScript in Ghost Kit blocks.
  • Rotate administrator session cookies and force password resets if injection is confirmed.

Patch Information

The vendor addressed the issue in the plugin file gutenberg/plugins/custom-code/index.php via changeset 3359701. Refer to the WordPress Custom Code Change for the exact code diff. Sites should install the latest available Ghost Kit release from the WordPress plugin repository.

Workarounds

  • Restrict Contributor-level access to trusted users only, and disable open user registration where not required.
  • Deploy a web application firewall rule to block Ghost Kit block payloads containing <script> and inline event handlers submitted by non-Editor roles.
  • Temporarily deactivate the Ghost Kit plugin on sites that cannot be patched immediately.
bash
# Configuration example: identify vulnerable Ghost Kit installations via WP-CLI
wp plugin get ghostkit --field=version
wp plugin update ghostkit

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.