CVE-2026-16273 PUBLISHED

Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta

Assigner: WPScan
Reserved: 20.07.2026 Published: 02.08.2026 Updated: 02.08.2026

The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post.

Product Status

Vendor Unknown
Product Narrative Publisher
Versions Default: unknown
  • affected from 0 to 1.0.7 (incl.)

Credits

  • Pablo González Pérez finder
  • Francisco José Ramírez Vicente and Iñigo Sánchez Enciso finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE