CVE-2026-88997: JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key
The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a higher-privileged user who reviews the affected post.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue and who is at risk from the resulting script execution?
A user with contributor-level access or higher can inject the malicious post meta key. The JavaScript executes in the browser session of a higher-privileged user who reviews the affected post in the admin interface.
Where does the malicious content need to be viewed for exploitation to occur?
The affected meta key is rendered in an admin-facing meta box. Exploitation requires a higher-privileged user to review the post containing the injected meta key.
Which plugin versions are affected?
Versions of JSM Show Post Metadata before 4.9.1 are affected.