Skip to main content
Loading…
    CVE-2026-4006 — The Simple Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' post meta (Custom Field) in all versions up to and including 2.6.2. This is due t — CVE Database · The Intelligence Room