<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Molongui Authorship – Author Boxes, Guest Authors &amp; Co-Authors (&lt;= 5.2.12) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/molongui-authorship--author-boxes-guest-authors--co-authors--5.2.12/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 09:51:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/molongui-authorship--author-boxes-guest-authors--co-authors--5.2.12/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored DOM-Based XSS in Molongui Authorship WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-molongui-xss/</link><pubDate>Sat, 10 Oct 2026 09:51:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-molongui-xss/</guid><description>The Molongui Authorship plugin is vulnerable to unauthenticated Stored DOM-based XSS via unsanitized href attributes in comment content, enabling arbitrary script execution in victim browsers.</description><content:encoded><![CDATA[<p>The Molongui Authorship - Author Boxes, Guest Authors &amp; Co-Authors plugin for WordPress is affected by a stored DOM-based Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-101920. The flaw stems from insufficient input sanitization and output escaping when handling the 'href' attribute within comment content.</p>
<p>The vulnerability is present in all versions up to and including 5.2.12. An unauthenticated attacker can exploit this by injecting malicious scripts into comment fields. The exploitation is facilitated by a logic flaw in the plugin's author-filter rewriter. Because the plugin's 'has_pro()' function returns false for the free version, the rewriter fails to append the '?m_bm=true' marker to anchors. Consequently, the byline script inadvertently selects and processes attacker-controlled 'href' attributes, leading to execution in the context of any user viewing the page. This vulnerability poses a significant risk to WordPress site integrity and user session security.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users visiting the affected pages. This can lead to session hijacking, unauthorized actions performed on behalf of authenticated users (including administrative accounts), and the defacement of the affected WordPress site. The vulnerability affects any site running the free version of the Molongui Authorship plugin (versions 5.2.12 and earlier).</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the 'Molongui Authorship - Author Boxes, Guest Authors &amp; Co-Authors' plugin to the latest version immediately once a patch is released by the vendor.</li>
<li>Disable comments globally or on posts containing authorship bylines if an update cannot be applied immediately to prevent active exploitation of the input vector.</li>
<li>Review web server logs for HTTP POST requests to comment submission endpoints that contain script-like content or suspicious 'href' attributes within comment data.</li>
<li>Implement a Content Security Policy (CSP) to restrict the execution of inline scripts and unauthorized external resources, mitigating the impact of successful XSS injections.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category></item></channel></rss>