What is CVE-2026-49466?
This is a stored Cross-Site Scripting (XSS) vulnerability in 'Draft List' WordPress plugin versions 2.6.3 and below. The flaw allows malicious script injection via the `[drafts]` shortcode or Draft List widget when the custom `template` option uses the `{{draft}}` placeholder inside HTML attributes. Users should update to a patched version or disable the affected functionality.
Azərbaycanca: Bu boşluq 'Draft List' WordPress plagininin 2.6.3 və daha aşağı versiyalarında saxlanılan Cross-Site Scripting (XSS) zəifliyidir. `[drafts]` shortcode-u və ya widget-da `{{draft}}` placeholder-inin istifadəsi zamanı xüsusi `template` seçimi vasitəsilə zərərli skript yerləşdirmək mümkündür. İstifadəçilər plagini ən son təhlükəsiz versiyaya yeniləməli və ya təsirlənən funksiyanı müvəqqəti söndürməlidirlər.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the 'Draft List' plugin are affected by CVE-2026-49466?
This stored XSS vulnerability affects 'Draft List' WordPress plugin versions 2.6.3 and below.
How can CVE-2026-49466 be exploited?
The flaw allows malicious script injection via the `[drafts]` shortcode or the Draft List widget when the custom `template` option uses the `{{draft}}` placeholder inside HTML attributes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.