Vulnerabilities and security researches fornarrative-so narrative-so
Direction: ascendingAug 05, 2026
Narrative Publisher # CVE-2026-16273
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 02, 2026
- Research Description
- The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post.
- Affected versions
-
max 1.0.7.
- Status
-
vulnerable