Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allows Stored XSS.

This issue affects Draft List: from n/a through 2.6.4.
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Draft List plugin fails to escape or sanitize user‑supplied content that is rendered on the site, allowing a malicious script to be persisted and executed the next time a page containing the draft list is viewed. This stored XSS flaw can lead to theft of session information, website defacement, or execution of arbitrary code by the victim’s browser.

Affected Systems

The issue affects installations of the Draft List plugin from any version up to and including 2.6.4. All users of the plugin before the 2.6.5 release are vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5, indicating medium severity. The EPSS score is not available, so no precise exploitation frequency is known. It is not listed in the CISA KEV catalog. Exploitation is straightforward; a user who can submit content through the plugin can inject malicious JavaScript that is stored in the database and later rendered to anyone who views a page with the draft list. The stored payload provides persistence and broad impact across users who view the affected content.

Generated by OpenCVE AI on August 19, 2026 at 08:32 UTC.

Remediation

Vendor Solution

Update the WordPress Draft List Plugin to the latest available version (at least 2.6.5).


OpenCVE Recommended Actions

  • Upgrade the Draft List plugin to version 2.6.5 or newer.
  • If an immediate update is not possible, deactivate or delete the plugin to block further exploitation.
  • As a temporary safeguard, examine any existing draft lists for embedded script elements and remove or encode them to prevent execution.

Generated by OpenCVE AI on August 19, 2026 at 08:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dartiss
Dartiss draft List
Wordpress
Wordpress wordpress
Vendors & Products Dartiss
Dartiss draft List
Wordpress
Wordpress wordpress

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allows Stored XSS. This issue affects Draft List: from n/a through 2.6.4.
Title WordPress Draft List plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Dartiss Draft List
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-19T14:39:48.484Z

Reserved: 2026-07-27T14:00:13.421Z

Link: CVE-2026-66603

cve-icon Vulnrichment

Updated: 2026-08-19T13:50:47.548Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T22:17:25.313

Modified: 2026-08-20T12:49:04.990

Link: CVE-2026-66603

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T20:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')