CVE-2026-10513
HIGH SEVERITYCVSS Score & Metrics
Base Score
7.2 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Vulnerability Description
The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 via parser-derived 'avatar' and 'url' author metadata. This is due to insufficient input sanitization and output escaping on user-supplied MF2 author properties processed by the unauthenticated webmention REST endpoint and rendered directly into HTML 'value' attributes by the edit-comment-form template without esc_attr() or esc_url(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a privileged user (moderator or administrator) opens the affected comment edit screen.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-79
Source
NVD
Vendor
pfefferle
Product
Webmention
External References
- https://plugins.trac.wordpress.org/browser/webmention/tags/5.7.0/includes/handler/class-mf2.php#L129
- https://plugins.trac.wordpress.org/browser/webmention/tags/5.7.0/templates/edit-comment-form.php#L15
- https://plugins.trac.wordpress.org/changeset/3583033/webmention
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5a4e144a-3c84-4da3-8fa6-e5fe9c897efe?source=cve
Discussion (0)
Add Comment
No comments yet. Be the first!