chiprook
← Security
SecurityOctober 10, 2026, 08:00

CVE-2026-93485: a single WordPress comment can take over the server

WordPress Core 4.7–7.1 is affected by CVE-2026-93485 (CVSS 7.1): an anonymous comment with a newline in the cite attribute bypasses KSES and, via bugs in wpautop() and wptexturize(), triggers stored XSS that escalates to RCE when an admin views it. Fixed in 7.1.1 and backported down to 4.7.36.

CVE-2026-93485: a single WordPress comment can take over the server
#WordPress
Read next
Security

cPanel flaw lets a hosting account run code as root and take over the server

Security

Elementor Pro CVE-2026-32475: patching doesn't remove the webshell

Security

WordPress 7.1.2 patches CVE-2026-87902 exploited within hours

Security

CVE-2026-12227: Critical unauthenticated LFI in Visual Composer WordPress plugin