Narrative Publisher, CVE-2026-16273
- CVE, Research URL
- Home page URL
- Application
- Published on
- Aug 02, 2026
- Research Description
- The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post.
- Affected versions
-
max 1.0.7.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| Narrative Publisher (CVE-2026-16273) , Aug 05, 2026 |