CVE-2026-16273: Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta
The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16273?
CVE-2026-16273 has been assigned a risk score of 36, indicating a significant vulnerability.
How do I fix CVE-2026-16273?
To fix CVE-2026-16273, update the Narrative Publisher WordPress plugin to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-16273?
Users with contributor-level access and above are affected by CVE-2026-16273 due to the stored XSS vulnerability.
What type of vulnerability is CVE-2026-16273?
CVE-2026-16273 is classified as a Cross-Site Scripting (XSS) vulnerability.
Can privileged users be impacted by CVE-2026-16273?
Yes, privileged users can be impacted by CVE-2026-16273 if they view posts that contain the stored JavaScript malicious payload.