Junglewise Threat Intelligence

CVE-2026-10513: WordPress Webmention Stored XSS in edit-comment-form

CVE-2026-10513 · Severity: high · CVSS 7.2 · Published 2026-06-30

Executive brief

The Webmention plugin for WordPress, which allows websites to notify each other when they are linked, contains a security flaw that allows unauthenticated attackers to inject malicious scripts. These scripts are stored on the website and trigger when a site administrator or moderator views the comment management screen. This could lead to unauthorized actions being performed by the attacker using the administrator's session, potentially compromising the entire website.

Technical details

The Webmention plugin for WordPress (up to version 5.8.0) is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping. Specifically, the unauthenticated webmention REST endpoint processes user-supplied MF2 author properties ('avatar' and 'url') which are then rendered directly into HTML 'value' attributes in the edit-comment-form template without using esc_attr() or esc_url(). An unauthenticated attacker can send a crafted webmention to inject arbitrary JavaScript. The payload executes when a privileged user, such as an administrator or moderator, accesses the affected comment edit screen in the WordPress dashboard. A patch is available in versions following 5.8.0.

Affected products

  • pfefferle Webmention up to and including 5.8.0

Timeline

  • 2026-06-30: disclosed: Vulnerability published to NVD and Wordfence database.
  • 2026-06-30: advisory

References