Impact
Ghost versions 5.2.0 through prior releases 6.61.9 allow an attacker who has no user credentials to exploit the Stripe Checkout flow. By doing so, the attacker can attach a paid subscription to an existing member, alter the member's display name, and inject arbitrary HTML into newsletters sent to that member. If the member's email client renders the injected content, the user may experience cross‑site scripting or HTML injection, enabling malicious payload delivery.
Affected Systems
TryGhost’s Ghost CMS, specifically versions 5.2.0 up to but not including 6.62.0, are affected. Any deployment of these releases that rely on Stripe Checkout for subscription management is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate‑to‑high severity, while no EPSS data is available and the vulnerability is not in the CISA KEV catalog. Attackers need only send a crafted Stripe Checkout request, an action that can be performed without authentication. If the targeted Ghost installation permits the flow, the exploit can lead to unintended subscription charges, user data tampering, and exposure of malicious content to subscribers. The lack of authentication requirement, combined with the ability to inject HTML into newsletters, increases the likelihood that the vulnerability can be leveraged in an active attack.
OpenCVE Enrichment