CVE-2026-88997
JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key
- Published
- Sep 23, 2026
- Updated
- Sep 23, 2026
- Assigning CNA
- WPScan
- Evidence observed
- Sep 23, 2026
Primary CVSS
cvelist_adp · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:HSummary
The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a higher-privileged user who reviews the affected post.
Sources
1JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.