Narrative Publisher
Narrative Publisher has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of August 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Narrative Publisher has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.
All of these findings were reported by Pablo González Pérez, Francisco José Ramírez Vicente and Iñigo Sánchez Enciso. Narrative Publisher is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-16273Narrative Publisher <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Narrative Publisher
Author
Narrative
This plugin connects your WordPress website with your Narrative App allowing you to publish your Narrative posts directly to your WordPress website. Please contact support@narrative.so for any help. Get Started Sign up with a free trial to Narrative here and download the app to get started. Technical info This plugin uses www.narrative.so to input your Narrative Posts into your WordPress website. Narrative has the ability to create and edit posts on your WordPress website When creating a post Narrative will input HTML and JS into your a post. For more info please see Narrative’s Terms and Conditions and Privacy Policy
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C