Impact
The Draft List plugin fails to escape or sanitize user‑supplied content that is rendered on the site, allowing a malicious script to be persisted and executed the next time a page containing the draft list is viewed. This stored XSS flaw can lead to theft of session information, website defacement, or execution of arbitrary code by the victim’s browser.
Affected Systems
The issue affects installations of the Draft List plugin from any version up to and including 2.6.4. All users of the plugin before the 2.6.5 release are vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating medium severity. The EPSS score is not available, so no precise exploitation frequency is known. It is not listed in the CISA KEV catalog. Exploitation is straightforward; a user who can submit content through the plugin can inject malicious JavaScript that is stored in the database and later rendered to anyone who views a page with the draft list. The stored payload provides persistence and broad impact across users who view the affected content.
OpenCVE Enrichment