Skip to content
Threat Feed
high threat exploited

Stored DOM-Based XSS in Molongui Authorship WordPress Plugin

The Molongui Authorship plugin is vulnerable to unauthenticated Stored DOM-based XSS via unsanitized href attributes in comment content, enabling arbitrary script execution in victim browsers.

CVE search metadata

CVE search record: CVE-2026-101920. Severity: high. CVSS: 7.2. KEV: no. Product: Molongui Authorship – Author Boxes, Guest Authors & Co-Authors (<= 5.2.12). Brief: Stored DOM-Based XSS in Molongui Authorship WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-molongui-xss/

The Molongui Authorship - Author Boxes, Guest Authors & Co-Authors plugin for WordPress is affected by a stored DOM-based Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-101920. The flaw stems from insufficient input sanitization and output escaping when handling the 'href' attribute within comment content.

The vulnerability is present in all versions up to and including 5.2.12. An unauthenticated attacker can exploit this by injecting malicious scripts into comment fields. The exploitation is facilitated by a logic flaw in the plugin's author-filter rewriter. Because the plugin's 'has_pro()' function returns false for the free version, the rewriter fails to append the '?m_bm=true' marker to anchors. Consequently, the byline script inadvertently selects and processes attacker-controlled 'href' attributes, leading to execution in the context of any user viewing the page. This vulnerability poses a significant risk to WordPress site integrity and user session security.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users visiting the affected pages. This can lead to session hijacking, unauthorized actions performed on behalf of authenticated users (including administrative accounts), and the defacement of the affected WordPress site. The vulnerability affects any site running the free version of the Molongui Authorship plugin (versions 5.2.12 and earlier).

Recommendation

  • Update the 'Molongui Authorship - Author Boxes, Guest Authors & Co-Authors' plugin to the latest version immediately once a patch is released by the vendor.
  • Disable comments globally or on posts containing authorship bylines if an update cannot be applied immediately to prevent active exploitation of the input vector.
  • Review web server logs for HTTP POST requests to comment submission endpoints that contain script-like content or suspicious 'href' attributes within comment data.
  • Implement a Content Security Policy (CSP) to restrict the execution of inline scripts and unauthorized external resources, mitigating the impact of successful XSS injections.

Immediate actions

Inventory instances of Molongui Authorship plugin and update to version > 5.2.12.

Web Operations 24h

Mitigations

Disable comment functionality on sites using affected plugin versions.

immediate Web Operations

CVE-2026-101920