{"id":"CVE-2026-88997","published":"2026-09-23T06:17:04.967","lastModified":"2026-09-23T18:12:32.050","description":"The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a higher-privileged user who reviews the affected post.","cvssScore":6.8,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/1699d3aa-29ca-4197-8e3b-0b03ecce751a/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}