What is CVE-2026-16273?
CVE-2026-16273 is a Stored XSS vulnerability in the Narrative Publisher WordPress plugin up to version 1.0.7, caused by missing write restrictions on a REST-exposed post meta field and improper escaping. It allows users with Contributor-level access and above to inject JavaScript that executes in the browsers of higher-privileged users. Immediate update of the plugin is strongly recommended.
Azərbaycanca: CVE-2026-16273 Narrative Publisher WordPress plugin-in 1.0.7 versiyasına qədər olan versiyalarında REST API üzərindən post meta sahəsinə yazı məhdudiyyətinin olmaması və nəticədə Stored XSS zəifliyidir. Bu, Contributor və daha yuxarı səviyyəli istifadəçilərə, daha yüksək imtiyazlı istifadəçilərin brauzerində JavaScript kodunun icrasına səbəb ola bilər. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Narrative Publisher plugin are affected by CVE-2026-16273?
This vulnerability affects all versions of the Narrative Publisher WordPress plugin up to, and including, version 1.0.7.
What minimum privilege level does an attacker need to exploit this Stored XSS vulnerability?
The attacker must have at least Contributor-level access, as this level is sufficient to write to the post meta field via the exposed REST API.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.