Description
The Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'comment (href attribute inside comment content)' parameter in all versions up to, and including, 5.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable in the free build because the plugin's author-filter rewriter never appends the ?m_bm=true marker to its own anchors (Plugin::has_pro() returns false), meaning every href the byline script selects and rewrites is fully attacker-controlled.
Published: 2026-10-10
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored DOM‑Based Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker to inject arbitrary JavaScript into a comment’s href attribute, which is stored by the Molongui Authorship plugin and then rendered by its front‑end script. Because the XSS is stored, it persists across sessions and is executed whenever any user visits a page containing the malicious comment. This can lead to credential theft, defacement, or malware delivery in the context of both authenticated and unauthenticated visitors. The weakness arises from insufficient input sanitization and lack of output escaping, a classic DOM‑based XSS identified as CWE‑79.

Affected Systems

WordPress sites that have the Molongui Authorship – Author Boxes, Guest Authors & Co‑Authors plugin installed in any version up to and including 5.2.12 are affected. The flaw exists in the free build because the plugin does not append a protective marker to rewritten anchors, allowing every href to be fully attacker‑controlled.

Risk and Exploitability

The CVSS score of 7.2 indicates a substantial risk. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via unauthenticated comment submission or content manipulation that allows an attacker to craft a malicious href value; once injected, the script runs in the context of any site visitor.

Generated by OpenCVE AI on October 10, 2026 at 09:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Molongui Authorship plugin to version 5.3.0 or later, where the vulnerable rewrite logic has been removed.
  • If an immediate update is not feasible, disable comment posting on the site or block unauthenticated users from submitting comments to prevent injection of malicious href values.
  • Until a patch or a confirmed workaround is available, consider removing the plugin entirely to eliminate the vulnerable code from the site.

Generated by OpenCVE AI on October 10, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'comment (href attribute inside comment content)' parameter in all versions up to, and including, 5.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable in the free build because the plugin's author-filter rewriter never appends the ?m_bm=true marker to its own anchors (Plugin::has_pro() returns false), meaning every href the byline script selects and rewrites is fully attacker-controlled.
Title Molongui Authorship <= 5.2.12 - Unauthenticated Stored DOM-Based Cross-Site Scripting via Comment href Attribute
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T07:41:43.905Z

Reserved: 2026-09-28T16:00:01.736Z

Link: CVE-2026-101920

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:03.213

Modified: 2026-10-10T08:17:03.213

Link: CVE-2026-101920

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T10:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')