Sceawere
Vulnerability Detail
CVE-2026-101920UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored DOM-XSS in Molongui Authorship
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 2h ago
- Vendor
- molongui
- Product
- Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'comment (href attribute inside comment content)' parameter in all versions up to, and including, 5.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable in the free build because the plugin's author-filter rewriter never appends the ?m_bm=true marker to its own anchors (Plugin::has_pro() returns false), meaning every href the byline script selects and rewrites is fully attacker-controlled.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T08:17:03.213Z",
"pubdate": "2026-10-10T08:17:03.213Z",
"executiveSummary": "The Molongui Authorship – Author Boxes, Guest Authors & Co-Authors plugin for WordPress is susceptible to Stored DOM-Based Cross-Site Scripting (XSS).\nThis vulnerability exists due to inadequate input sanitization and output escaping within the plugin's comment handling logic.\nThe flaw allows unauthenticated remote attackers to inject arbitrary JavaScript payloads into comments, which are subsequently executed in the browsers of users viewing the affected pages.\nThe issue stems from a failure in the author-filter rewriter mechanism, which incorrectly handles href attributes within comment content.\nBecause the plugin does not append the expected m_bm=true marker to its own anchors in the free build, the byline script inadvertently processes and rewrites attacker-controlled href attributes.\nSuccessful exploitation results in the execution of unauthorized scripts in the context of the victim's session, potentially leading to session hijacking, unauthorized actions, or information disclosure.\nThe vulnerability affects all versions of the plugin up to and including 5.2.12.",
"technicalDetails": "The vulnerability is a Stored DOM-Based XSS residing in the comment processing logic of the Molongui Authorship plugin.\nThe root cause of the vulnerability is insufficient input sanitization of the href attribute within comment content and a flaw in the plugin's JavaScript-based author-filter rewriter.\nWhen a user submits a comment containing an HTML anchor tag, the plugin attempts to intercept and rewrite these links. However, the logic for this rewriter is flawed in the free build of the plugin.\nThe plugin uses a helper function, Plugin::has_pro(), to determine if the premium version is active. In the free version, this returns false, causing the script to skip the validation checks (specifically the presence of the ?m_bm=true marker) that would otherwise protect the href attribute from malicious modification.\nConsequently, the JavaScript byline script blindly selects and rewrites all href attributes present within comment content. An attacker can craft a comment containing a payload in the href attribute, such as 'javascript:alert(1)' or other malicious code.\nBecause the DOM rewriter does not properly sanitize these attributes before inserting them back into the page's Document Object Model, the browser executes the injected script when a user navigates to a page where the malicious comment is displayed.\nThe attack flow proceeds as follows: 1) An unauthenticated attacker submits a comment containing a malicious payload disguised within an href attribute. 2) The WordPress backend stores the comment in the database without sufficient sanitization of the attribute. 3) When an authorized user or administrator loads a page containing the comment, the Molongui JavaScript byline script executes on the client side. 4) The script identifies the malicious anchor tag and, due to the missing marker validation, processes the attacker-controlled href attribute. 5) The browser interprets the injected script, leading to DOM-based XSS execution.\nThis vulnerability is particularly critical as it does not require administrative authentication and is stored, meaning it can affect any user, including high-privileged administrators, simply by visiting the page where the comment resides.\nThe impact includes full compromise of the user's session context, enabling the execution of arbitrary JavaScript to steal session cookies, perform unauthorized actions on behalf of the user, or redirect users to malicious domains."
}