Impact
The vulnerability allows an attacker to inject arbitrary JavaScript into a comment’s href attribute, which is stored by the Molongui Authorship plugin and then rendered by its front‑end script. Because the XSS is stored, it persists across sessions and is executed whenever any user visits a page containing the malicious comment. This can lead to credential theft, defacement, or malware delivery in the context of both authenticated and unauthenticated visitors. The weakness arises from insufficient input sanitization and lack of output escaping, a classic DOM‑based XSS identified as CWE‑79.
Affected Systems
WordPress sites that have the Molongui Authorship – Author Boxes, Guest Authors & Co‑Authors plugin installed in any version up to and including 5.2.12 are affected. The flaw exists in the free build because the plugin does not append a protective marker to rewritten anchors, allowing every href to be fully attacker‑controlled.
Risk and Exploitability
The CVSS score of 7.2 indicates a substantial risk. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via unauthenticated comment submission or content manipulation that allows an attacker to craft a malicious href value; once injected, the script runs in the context of any site visitor.
OpenCVE Enrichment