
JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key
| CVE ID | CVE-2026-88997 |
| Status | PUBLISHED |
| CNA | WPScan |
| Published | 2026-09-23 |
| Updated | 2026-09-23 |
| CWE | CWE-79: Cross-Site Scripting (XSS) |
The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box. This allows users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a higher-privileged user who reviews the affected post (stored XSS).
| Field | Value |
|---|---|
| Vendor | Unknown |
| Product | JSM Show Post Metadata |
| Affected versions | from 0 before 4.9.1 |
| Default status | unaffected |
| Fixed in | 4.9.1 |
Update the JSM Show Post Metadata plugin to version 4.9.1 or later.
Source: WPScan (CNA) — CVE Record for CVE-2026-88997