Vendor
The Molongui Authorship plugin is vulnerable to unauthenticated Stored DOM-based XSS via unsanitized href attributes in comment content, enabling arbitrary script execution in victim browsers.