chiprook
← Security
SecuritySeptember 22, 2026, 13:03

WordPress Comment2Shell flaw turns anonymous comment XSS into RCE

A flaw in WordPress core, tracked as CVE-2026-93485 and dubbed "Comment2Shell," let an anonymous visitor post a comment that planted a hidden script on the page. If a logged-in administrator opened it, the script could run code on the site's server. WordPress fixed the issue on September 17 in version 7.1.1 and urged site owners to update immediately.

WordPress Comment2Shell flaw turns anonymous comment XSS into RCE
#WordPress
Read next
Security

EU auditors: poor information sharing between member states creates security gaps

Security

Anthropic reports autonomous AI-agent attacks as physical AI security demand grows

Security

Mimecast: security effectiveness drops despite higher spending

Security

5G-Shark: cheap fake base station still tracks 5G subscribers