CVE-2026-49466 is a stored Cross-Site Scripting (XSS) vulnerability in the Draft List WordPress plugin, affecting versions 2.6.3 and below. An authenticated Contributor can store a malicious title that breaks out of an attribute in a site-configured Draft List template, executing JavaScript for visitors who load the public page. The issue is fixed in version 2.6.4.
The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the external URL embed feature in post content. This allows a Contributor attacker to submit a pending post containing an inert-looking URL token that executes attacker-controlled JavaScript when an Administrator or Editor previews or reviews the post.
The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability. This vulnerability is caused by the absence of WordPress's `esc_url()` escaping function on the `$url` variable before it is rendered into HTML content. The variable is constructed from `home_url( add_query_arg( array(), $wp->request ) )` and is concatenated directly into an HTML `href` attribute on ever [truncated]
CVE-2026-9104 is a stored cross-site scripting issue in the Draft List WordPress plugin. An authenticated attacker with author-level access or higher can place malicious content in a draft post title, and the payload can execute when another user views the affected page, especially when that viewer lacks edit capabilities. Because the vulnerability is stored and can affect unauthenticated users, subscribe [truncated]