Executive brief
The Narrative Publisher WordPress plugin is a content publishing tool used by WordPress sites. The plugin fails to properly secure and sanitize a REST API field accessible to contributor-level users, allowing them to inject malicious JavaScript that executes when administrators or editors view their posts. This can lead to administrative account compromise and site-wide data theft.
Technical details
This is a stored cross-site scripting (XSS) vulnerability (CWE-79) in the Narrative Publisher plugin's handling of the narrative_post_script post meta field. The vulnerability stems from two flaws: (1) the REST API endpoint does not restrict write access to this meta field for contributor-level users, and (2) the block render callback base64-decodes and returns the meta value without escaping HTML entities. An authenticated user with contributor access or higher can send a REST API request with a base64-encoded JavaScript payload in the narrative_post_script meta field of a pending or published post. When an editor, administrator, or anonymous visitor views the post, the payload is decoded and executed in their browser within the authenticated context, enabling session hijacking and account takeover.
Affected products
- Narrative Narrative Publisher through 1.1.0
Timeline
- 2026-07-21: disclosed
- 2026-08-02: advisory
- 2026-08-28: other: Last updated