PT-2026-67102 · WordPress · Narrative Publisher
CVE-2026-16273
·
Published
2026-08-02
·
Updated
2026-08-02
CVSS v3.1
4.6
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Narrative Publisher versions prior to 1.0.8
Description
Insufficient restriction of write access to a REST-exposed post meta field and a failure to escape data during rendering allow users with contributor-level access and above to perform a Stored Cross-Site Scripting (XSS) attack. This occurs via the
narrative post script post meta, enabling the storage of malicious JavaScript that executes in the browser of any higher-privileged user who views the affected post.Recommendations
Update Narrative Publisher to version 1.0.8 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Narrative Publisher