Stored Cross-Site Scripting Vulnerability in Draft List WordPress Plugin
CVE-2026-49466

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
12 August 2026

What is CVE-2026-49466?

The Draft List plugin for WordPress, which helps manage unpublished content, is susceptible to stored cross-site scripting (XSS) attacks in versions 2.6.3 and earlier. This vulnerability occurs when a user utilizes the documented custom template option that incorporates the {{draft}} placeholder within an HTML attribute. An attacker can input a crafted payload in the post_title, escaping the attribute context, allowing malicious JavaScript code to execute in the browsers of visitors accessing public pages. The issue is mitigated in version 2.6.4, which safeguards against this exploitation.

Affected Version(s)

draft-list < 2.6.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.