
CVE-2026-9104 The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up to, and including, 2.6.3 due to insufficient in… https://www.cve.org/CVERecord?id=CVE-2026-9104
Post summary
The Draft List plugin for WordPress up to version 2.6.3 is vulnerable to stored XSS via the draft post title, as detailed in CVE-2026-9104.
