WordPress Comment2Shell flaw turns anonymous comment XSS into RCE
A flaw in WordPress core, tracked as CVE-2026-93485 and dubbed "Comment2Shell," let an anonymous visitor post a comment that planted a hidden script on the page. If a logged-in administrator opened it, the script could run code on the site's server. WordPress fixed the issue on September 17 in version 7.1.1 and urged site owners to update immediately.
- Flaw tracked as CVE-2026-93485, dubbed Comment2Shell
- Anonymous comment planted a hidden script on the page
- Script ran server-side code when an admin opened the page
- Fixed on September 17 in WordPress version 7.1.1
Read next
Security