🔐 CVE Alert

CVE-2026-16273

UNKNOWN 0.0

Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post.

Vendor unknown
Product narrative publisher
Published Aug 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown narrative publisher

Be the first to know when new unknown vulnerabilities affecting unknown narrative publisher are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Narrative Publisher
0 ≤ 1.0.7

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/c98113a9-ee8a-4a24-8b2f-d506b99bba1c/

Credits

Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan