Webmention
Webmention has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 2 high. 2026 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (50%). Other recurring categories include Server-Side Request Forgery (SSRF).
Every one of the 4 issues recorded for Webmention has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (2) reported by Duong Quang Hao. Webmention is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-10513Webmention <= 5.8.0 - Unauthenticated Stored Cross-Site Scripting via MF2 'photo'/'url' Author Properties
Read the full analysisVulnerability Records

Webmention
Author
Matthias Pfefferle
When you link to a website you can send it a Webmention to notify it and then that website may display your post as a comment, like, or other response, and presto, you’re having a conversation from one site to another! A Webmention is a notification that one URL links to another. Sending a Webmention is not limited to blog posts, and can be used for additional kinds of content and responses as well. For example, a response can be an RSVP to an event, an indication that someone “likes” another post, a “bookmark” of another post, and many others. Webmention enables these interactions to happen across different websites, enabling a distributed social web. The Webmention plugin supports the Webmention protocol, giving you support for sending and receiving Webmentions. It offers a simple built in presentation.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C