Ghost

Ghost has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Insertion Of Sensitive Information Into Log File, behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for Ghost has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Ghost is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Ghost vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.5CVE-2016-10983

Ghost <= 0.5.5 - Missing Authorization Checks

Read the full analysis

Vulnerability Records

2 records
Ghost banner
Latestv1.6.0
3.6(7)
72/100
Last Updated
2024-11-15 (2y ago)
Active Installs
500+
Downloads
43,877
Requires WP
4.2.0+
Requires PHP
0+
Tested up to
WP 6.7.7
Created
2013-09-03 (13y ago)

Ghost Migrator: The easy way to migrate data to Ghost The official Ghost plugin allows you to export your WordPress data in a JSON format that can be imported quickly and easily by the Ghost publishing platform. Features Overview The Ghost Migrator plugin will export as much blog and publication data as it can into a clean set of exported files. Posts, pages, tags and authors are all automatically exported and recreated for Ghost Tags will be migrated, but not categories. If needed you can convert your categories to tags before exporting. Ghost does not have built-in comments, but it does integrate with many comment platforms if you want to migrate your comments there. No custom fields, meta, shortcodes, post types, taxonomies or binary files will be migrated. Just regular posts, pages, tags and images Passwords are not migrated – after importing to Ghost, each user may perform a password reset to gain access to their Ghost account Docs & Support You can find docs, FAQ and more detailed information about Ghost on ghost.org. If you’re unable to find the answer to your question in our FAQ or in any of the documentation, try searching the Ghost support forum – if you still don’t find the answer you need, post a new topic! Bug reports Bug reports for the Ghost Migrator plugin are welcome over on our GitHub repository. Please note that GitHub is not a support forum, and that issues that aren’t properly qualified as bugs will be closed. Further Reading For more information about Ghost and help getting started with the platform, check out: The Ghost official homepage The Ghost Support & FAQ The Ghost Forum & Community Follow Ghost on Twitter

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C