PT-2026-71280 · WordPress · Draft List
CVE-2026-49466
·
Published
2026-08-12
·
Updated
2026-08-12
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Draft List versions prior to 2.6.4
Description
Stored Cross-Site Scripting (XSS) occurs in the
[drafts] shortcode and Draft List widget when the custom template option places the {{draft}} placeholder inside an HTML attribute. The system inserts the raw post title into the {{draft}} placeholder when the viewer lacks post-editing permissions. Since the template is sanitized before the placeholder is replaced, a user with Contributor privileges can store a payload in the title that breaks out of the HTML attribute to execute JavaScript for visitors viewing the public page.Recommendations
Update Draft List to version 2.6.4.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Draft List