CVE-2026-66603: WordPress Draft List plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allows Stored XSS.
This issue affects Draft List: from n/a through 2.6.4.
Affected Software
1 affected component
Draft List simple-draft-list<=2.6.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Draft List pluginto a version that resolves this vulnerability.Fixed in 2.6.5
Event History
Aug 18, 2026
CVE Published
via MITRE·10:02 PM
Data Sourced
via MITRE·10:02 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
Exploitation requires network access, low-level privileges, and user interaction. The vulnerable behavior is stored XSS, so attacker-supplied content can persist and execute when a user views the affected page.
2
Which deployments should be considered affected?
Draft List simple-draft-list versions through 2.6.4 are affected. The provided data does not state whether the plugin's default configuration is vulnerable.