SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16273

MEDIUM · CVSS 4.6 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

The Narrative Publisher WordPress plugin allows users with contributor-level access and above to write unvalidated JavaScript into a REST-exposed post meta field, which can execute in the browsers of higher-privileged users viewing the affected posts. This vulnerability could lead to cross-site scripting (XSS) attacks, potentially compromising user sessions and sensitive information. WordPress site administrators and developers using this plugin should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-16273
Severity
MEDIUM
CVSS
4.6
EPSS
0.13%
WordPress Java

Original NVD Description

The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post.