Stored Cross-Site Scripting Vulnerability in Simple Draft List Plugin for WordPress
CVE-2026-4006
6.4MEDIUM
What is CVE-2026-4006?
The Simple Draft List plugin for WordPress suffers from a stored cross-site scripting vulnerability through the 'display_name' post meta field. Due to inadequate input sanitization and output escaping, an attacker with Contributor-level access can insert malicious web scripts into pages. This vulnerability occurs because the plugin does not properly handle the author’s display name within the shortcode output, specifically when the author URL is absent. As a result, these scripts can execute when users access the affected pages, posing a significant risk to the web application and its users.
Affected Version(s)
Draft List 0 <= 2.6.2