Stored XSS Vulnerability in Simple Draft List by David Artiss
CVE-2026-66603

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 August 2026

What is CVE-2026-66603?

A vulnerability in the Simple Draft List plugin developed by David Artiss permits the improper handling of user input, leading to stored Cross-site Scripting (XSS) attacks. This flaw affects versions of the plugin up to and including 2.6.4, allowing attackers to inject malicious scripts into web pages that are viewed by other users. As a result, unsuspecting users may be exposed to harmful actions executed without their consent, compromising the security of both user data and the integrity of the website.

Affected Version(s)

Draft List <= 2.6.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

V1T | Patchstack Bug Bounty Program
.