WordPress Plugin Vulnerabilities

JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key

Description

The plugin does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a higher-privileged user who reviews the affected post.

Proof of Concept

Affects Plugins

Fixed in 4.9.1

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
pervinzahidli
Submitter
Pervin Zahidli
Verified
Yes

Timeline

Publicly Published
2026-09-21 (about 2 days ago)
Added
2026-09-21 (about 1 day ago)
Last Updated
2026-09-21 (about 1 day ago)

Other