WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
Overview
A recently discovered vulnerability in WordPress, known as 'Comment2Shell' and tracked as CVE-2026-93485, allows anonymous users to leave comments that can inject hidden scripts into web pages. If an administrator then views the page, the script can execute code on the server, potentially allowing attackers to take control of the site. This issue was addressed in version 7.1.1, released on September 17, 2023. Site owners are urged to update their WordPress installations immediately to protect against this flaw, which poses significant risks to website security. Failure to patch could leave sites vulnerable to remote code execution attacks.
Key Takeaways
- Affected Systems: WordPress core versions prior to 7.1.1.
- Action Required: Update to WordPress version 7.
- Timeline: Disclosed on September 17, 2023
Original Article Summary
A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away. There is
Impact
WordPress core versions prior to 7.1.1.
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Disclosed on September 17, 2023
Remediation
Update to WordPress version 7.1.1 or later.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, Patch, and 3 more.