Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-88997 — JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key | Kitploit
Tools/GitHubGitHub/pervinzahidli/cve-2026-88997
Vulnerability AnalysisExploitationWeb SecurityPapers & Research
GitHubpervinzahidli/cve-2026-88997

CVE-2026-88997

JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key

View Repository
1 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-88997

JSM Show Post Metadata < 4.9.1 — Contributor+ Stored XSS via Custom Field Meta Key

CVE IDCVE-2026-88997
StatusPUBLISHED
CNAWPScan
Published2026-09-23
Updated2026-09-23
CWECWE-79: Cross-Site Scripting (XSS)

Description

The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box. This allows users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a higher-privileged user who reviews the affected post (stored XSS).

Affected Product

FieldValue
VendorUnknown
ProductJSM Show Post Metadata
Affected versionsfrom 0 before 4.9.1
Default statusunaffected
Fixed in4.9.1

Vulnerability Type

  • Type: Stored Cross-Site Scripting (XSS)
  • Vector: Custom Field Meta Key rendered unescaped into an inline event-handler attribute
  • Privilege required: Contributor or above
  • Impact: JavaScript execution in a higher-privileged user's session (e.g. editor/administrator reviewing the post)

Remediation

Update the JSM Show Post Metadata plugin to version 4.9.1 or later.

Credits

  • Finder: pervinzahidli
  • Coordinator: WPScan

References

  • WPScan advisory — exploit, VDB entry, technical description

Source: WPScan (CNA) — CVE Record for CVE-2026-88997

Download Tool