WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
Security

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

The Hacker News · Sep 22, 2026

Back to News
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
Security September 22, 2026

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away. There is

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.