{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/molongui/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:molongui:molongui_authorship_-_author_boxes,_guest_authors_\u0026_co-authors:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-101920"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Molongui Authorship – Author Boxes, Guest Authors \u0026 Co-Authors (\u003c= 5.2.12)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Molongui"],"content_html":"\u003cp\u003eThe Molongui Authorship - Author Boxes, Guest Authors \u0026amp; Co-Authors plugin for WordPress is affected by a stored DOM-based Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-101920. The flaw stems from insufficient input sanitization and output escaping when handling the 'href' attribute within comment content.\u003c/p\u003e\n\u003cp\u003eThe vulnerability is present in all versions up to and including 5.2.12. An unauthenticated attacker can exploit this by injecting malicious scripts into comment fields. The exploitation is facilitated by a logic flaw in the plugin's author-filter rewriter. Because the plugin's 'has_pro()' function returns false for the free version, the rewriter fails to append the '?m_bm=true' marker to anchors. Consequently, the byline script inadvertently selects and processes attacker-controlled 'href' attributes, leading to execution in the context of any user viewing the page. This vulnerability poses a significant risk to WordPress site integrity and user session security.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users visiting the affected pages. This can lead to session hijacking, unauthorized actions performed on behalf of authenticated users (including administrative accounts), and the defacement of the affected WordPress site. The vulnerability affects any site running the free version of the Molongui Authorship plugin (versions 5.2.12 and earlier).\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the 'Molongui Authorship - Author Boxes, Guest Authors \u0026amp; Co-Authors' plugin to the latest version immediately once a patch is released by the vendor.\u003c/li\u003e\n\u003cli\u003eDisable comments globally or on posts containing authorship bylines if an update cannot be applied immediately to prevent active exploitation of the input vector.\u003c/li\u003e\n\u003cli\u003eReview web server logs for HTTP POST requests to comment submission endpoints that contain script-like content or suspicious 'href' attributes within comment data.\u003c/li\u003e\n\u003cli\u003eImplement a Content Security Policy (CSP) to restrict the execution of inline scripts and unauthorized external resources, mitigating the impact of successful XSS injections.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T09:51:27Z","date_published":"2026-10-10T09:51:27Z","id":"https://feed.craftedsignal.io/briefs/2026-10-molongui-xss/","summary":"The Molongui Authorship plugin is vulnerable to unauthenticated Stored DOM-based XSS via unsanitized href attributes in comment content, enabling arbitrary script execution in victim browsers.","title":"Stored DOM-Based XSS in Molongui Authorship WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-molongui-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Molongui","version":"https://jsonfeed.org/version/1.1"}