Stored Cross-Site Scripting Vulnerability in Simple Draft List Plugin for WordPress
CVE-2026-4006
What is CVE-2026-4006?
The Simple Draft List plugin for WordPress suffers from a stored cross-site scripting vulnerability through the 'display_name' post meta field. Due to inadequate input sanitization and output escaping, an attacker with Contributor-level access can insert malicious web scripts into pages. This vulnerability occurs because the plugin does not properly handle the author’s display name within the shortcode output, specifically when the author URL is absent. As a result, these scripts can execute when users access the affected pages, posing a significant risk to the web application and its users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Draft List * <= 2.6.2