Stored Cross-Site Scripting Vulnerability in Draft List WordPress Plugin
CVE-2026-49466
6.5MEDIUM
What is CVE-2026-49466?
The Draft List plugin for WordPress, which helps manage unpublished content, is susceptible to stored cross-site scripting (XSS) attacks in versions 2.6.3 and earlier. This vulnerability occurs when a user utilizes the documented custom template option that incorporates the {{draft}} placeholder within an HTML attribute. An attacker can input a crafted payload in the post_title, escaping the attribute context, allowing malicious JavaScript code to execute in the browsers of visitors accessing public pages. The issue is mitigated in version 2.6.4, which safeguards against this exploitation.
Affected Version(s)
draft-list < 2.6.4