Ad

CVE-2026-88997

NONE
Обновлено 23 сентября 2026
Meta
Параметр Значение
Уязвимые версии до 4.9.1
Поставщик Meta
Публичный эксплойт Нет

The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a higher-privileged user who reviews the affected post.