PT-2026-71280 · WordPress · Draft List

CVE-2026-49466

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Draft List versions prior to 2.6.4
Description Stored Cross-Site Scripting (XSS) occurs in the [drafts] shortcode and Draft List widget when the custom template option places the {{draft}} placeholder inside an HTML attribute. The system inserts the raw post title into the {{draft}} placeholder when the viewer lacks post-editing permissions. Since the template is sanitized before the placeholder is replaced, a user with Contributor privileges can store a payload in the title that breaks out of the HTML attribute to execute JavaScript for visitors viewing the public page.
Recommendations Update Draft List to version 2.6.4.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49466
GHSA-XXX9-HFQP-F83F

Affected Products

Draft List