CVE-2026-16273
Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post.
| Vendor | unknown |
| Product | narrative publisher |
| Published | Aug 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown narrative publisher
Be the first to know when new unknown vulnerabilities affecting unknown narrative publisher are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Narrative Publisher
0 ≤ 1.0.7
References
Credits
Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan