CVE-2026-49466: Draft List - Contributor Stored Cross-Site Scripting via Draft Title in Custom Drafts Template Attributes
Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to stored Cross-Site Scripting (XSS) in the [drafts] shortcode and Draft List widget when the documented custom template option places the {{draft}} placeholder inside an HTML attribute. The vulnerable code inserts the raw draft posttitle into {{draft}} when the current viewer cannot edit posts. Because the template is sanitized before {{draft}} replacement, a Contributor can store a quote-only title payload that breaks out of an attribute in a site-configured Draft List template and executes JavaScript for visitors who load the public page. Version 2.6.4 fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Draft List pluginto a version that resolves this vulnerability.Fixed in 2.6.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49466?
The severity of CVE-2026-49466 is rated medium with a score of 6.5.
How do I fix CVE-2026-49466?
To fix CVE-2026-49466, update the WordPress Draft List plugin to version 2.6.4 or later.
What are the risks associated with CVE-2026-49466?
CVE-2026-49466 can lead to stored Cross-Site Scripting (XSS) attacks.
Which versions are affected by CVE-2026-49466?
CVE-2026-49466 affects versions of the Draft List plugin up to 2.6.3.
What type of vulnerability is CVE-2026-49466?
CVE-2026-49466 is classified as a stored Cross-Site Scripting (XSS) vulnerability.