CVE-2026-88997

NONE
Updated Sep 23, 2026
Meta
Parameter Value
Affected Versions before 4.9.1
Vendor Meta
Public PoC No

The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a higher-privileged user who reviews the affected post.