PT-2026-53940 · WordPress · Webmention
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Webmention versions prior to 5.8.1
Description
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping of user-supplied Microformat 2 (MF2) author properties. An unauthenticated attacker can inject arbitrary web scripts via the
avatar and url author metadata processed by the unauthenticated webmention REST endpoint. These scripts are rendered directly into HTML value attributes by the edit-comment-form template without the use of esc attr() or esc url() functions. The injected scripts execute when a privileged user, such as a moderator or administrator, opens the affected comment edit screen.Recommendations
Update Webmention to a version later than 5.8.0.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webmention