CyberRota Analysis
AI-GeneratedThe Narrative Publisher WordPress plugin allows users with contributor-level access and above to write unvalidated JavaScript into a REST-exposed post meta field, which can execute in the browsers of higher-privileged users viewing the affected posts. This vulnerability could lead to cross-site scripting (XSS) attacks, potentially compromising user sessions and sensitive information. WordPress site administrators and developers using this plugin should prioritize immediate remediation to mitigate the risk of exploitation.
Original NVD Description
The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post.