CVE-2026-93485: a single WordPress comment can take over the server
WordPress Core 4.7–7.1 is affected by CVE-2026-93485 (CVSS 7.1): an anonymous comment with a newline in the cite attribute bypasses KSES and, via bugs in wpautop() and wptexturize(), triggers stored XSS that escalates to RCE when an admin views it. Fixed in 7.1.1 and backported down to 4.7.36.
- Affects WordPress 4.7–7.1; patched in 7.1.1
- An anonymous comment alone triggers stored XSS with no click
- XSS escalates to server RCE via an admin session
- CVSS 3.1 score is 7.1 (High); reported by Rafie Muhammad
Read next
Security