Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 14 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dartiss
Dartiss draft List Wordpress Wordpress wordpress |
|
| Vendors & Products |
Dartiss
Dartiss draft List Wordpress Wordpress wordpress |
Wed, 12 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to stored Cross-Site Scripting (XSS) in the `[drafts]` shortcode and Draft List widget when the documented custom `template` option places the `{{draft}}` placeholder inside an HTML attribute. The vulnerable code inserts the raw draft `post_title` into `{{draft}}` when the current viewer cannot edit posts. Because the template is sanitized before `{{draft}}` replacement, a Contributor can store a quote-only title payload that breaks out of an attribute in a site-configured Draft List template and executes JavaScript for visitors who load the public page. Version 2.6.4 fixes the issue. | |
| Title | Draft List - Contributor Stored Cross-Site Scripting via Draft Title in Custom Drafts Template Attributes | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-13T14:28:22.736Z
Reserved: 2026-05-30T04:17:43.094Z
Link: CVE-2026-49466
Updated: 2026-08-13T14:28:15.357Z
Status : Received
Published: 2026-08-12T20:17:44.713
Modified: 2026-08-13T15:19:41.293
Link: CVE-2026-49466
No data.
OpenCVE Enrichment
Updated: 2026-08-12T23:00:05Z