---
id: CVE-2026-16273
title: >-
  The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write
  access to a REST-exposed post meta field or escape it when rendering, allowing
  users with contributor-level access and above to store JavaScript that
  executes…
summary: >-
  The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write
  access to a REST-exposed post meta field or escape it when rendering, allowing
  users with contributor-level access and above to store JavaScript that
  executes…
severity: none
published: '2026-08-02'
updated: '2026-08-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16273'
references:
  - url: 'https://wpscan.com/vulnerability/c98113a9-ee8a-4a24-8b2f-d506b99bba1c/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-08-02T13:18:29.376Z'
epss: 0.00226
epssPercentile: 0.11818
---

## Overview

The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
