CVE-2026-88997 PUBLISHED

JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key

Assigner: WPScan
Reserved: 10.09.2026 Published: 23.09.2026 Updated: 23.09.2026

The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a higher-privileged user who reviews the affected post.

Product Status

Vendor Unknown
Product JSM Show Post Metadata
Versions Default: unaffected
  • affected from 0 to 4.9.1 (excl.)

Credits

  • pervinzahidli finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE