Stored DOM-Based Cross-Site Scripting in Molongui Authorship Plugin for WordPress
CVE-2026-101920

7.2HIGH

What is CVE-2026-101920?

The Molongui Authorship plugin for WordPress is susceptible to stored DOM-based cross-site scripting due to improper input validation and a lack of effective output escaping. The vulnerability arises through the 'comment' parameter, specifically in the href attribute of comment content, allowing unauthenticated attackers to inject malicious scripts into web pages. Exploitation is heightened by the design of the plugin, as it fails to append necessary markers to certain anchors, granting full control to the attacker over the relevant href attributes. This can lead to script execution when users access the compromised pages.

Affected Version(s)

Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress 0 <= 5.2.12

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

crow
.