[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fR9kx5-dekSuJr2NvVtmF1TQMjwbQkkRobiKs2aPLFFI":3},{"article":4,"iocs":39},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":31},"a4766836-e571-4b55-81cd-d9e13779f41d","WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session","wordpress-comment2shell-flaw-can-turn-anonymous-comment-xss-into-rce-via-admin-s-fc67da","A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed \"Comment2Shell,\" on September 17 in version 7.1.1 and told site owners to update right away. There is","A vulnerability in WordPress core, dubbed 'Comment2Shell' (CVE-2026-93485), allowed anonymous users to inject malicious scripts via comments. If an administrator later viewed the page, the script could execute, enabling an attacker to upload a webshell and gain server control. WordPress released version 7.1.1 to fix the flaw, affecting versions from 4.7 to 7.1.","WordPress Comment2Shell flaw allows anonymous comment XSS to RCE via admin session.","WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Swati KhandelwalSep 22, 2026Vulnerability \u002F Web Security A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed \"Comment2Shell,\" on September 17 in version 7.1.1 and told site owners to update right away. There is no sign it has been used in attacks, and it is not on the U.S. government's list of actively exploited software flaws. Patchstack, the company that assigned that identifier, rated the flaw 7.1 out of 10 on the CVSS scale. WordPress checks a comment for dangerous HTML when it is saved, then reformats it when the page is shown, and the flaw sat in the gap between those two steps. Rafie Muhammad, the security researcher who reported the bug, laid out the full chain in a write-up on September 21. The trick was a line break placed inside the attribute of an allowed HTML tag in the comment. When WordPress reformatted the comment for display, one of its steps broke that tag apart and moved the attacker's text into a spot where the browser treated it as a live event handler. The handler ran automatically as the page loaded, with no click required. The script ran in the browser of whoever opened the page, whether or not they were logged in, and it acted with that person's access level to the site. Running code on the server needed one more condition. A logged-in administrator had to open the page carrying the comment. The script could then use the administrator's own session to upload a plugin containing a web shell, a small file that executes whatever commands an attacker sends. Uploading a plugin this way is a known route from an administrator's browser to control of the server. The attack also depended on how a site displayed its comments. It worked on sites that use a block theme, or a classic theme that formats comments the same way, and not on others. For any of this to happen, the comment had to appear on the page first. WordPress described the flaw as exploitable only \"subject to comment approval.\" But comment moderation is off by default, and the setting that holds a first-time commenter can be worked around, so a comment could reach the page without anyone approving it. As Patchstack put it, \"moderation isn't a security control.\" What to do Update to WordPress 7.1.1, or to the latest release on your branch if it still gets security fixes. The affected versions run from 4.7 through 7.1, and these are the fixed releases for the current branches: WordPress 7.1: update to 7.1.1 WordPress 7.0: update to 7.0.5 WordPress 6.9: update to 6.9.8 Older branches, back to 4.7: install the fixed release for your branch, as far back as 4.7.36, listed for each branch in WordPress's release documentation A site that cannot update at once can shut the way in by closing comments on posts or turning comments off across the site, and a web application firewall or a security plugin may block the crafted comment. Neither WordPress nor the researcher published a separate workaround. Updating fixes the flaw, but it does not undo any change an attacker already made. A site with reason to think it was targeted should also look for plugins or files it does not recognize. WordPress 7.1.1 fixed 11 security problems in all. This comment flaw was the only one that an attacker with no account could access, and most of the others required a logged-in user with some level of access. The same release fixed a second flaw, called Click2Shell, in which a crafted link could make WordPress install a theme and, together with a second weakness in that theme, run code on the server. It, too, required a logged-in administrator to open the link. WordPress core has had other serious flaws this year. In July, a bug called wp2shell let attackers run code with no login at all, and U.S. authorities later listed it as used in real attacks. In August, researchers exploited a scripting flaw in the login page to execute code as an administrator. These are separate flaws from the comment bug. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Vulnerability, Web Security, WordPress ⚡ Top Stories This Week Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. How to Evaluate a Unified Security Platform Using a One-Incident Test Stop Trying to Control AI Behavior. Control What AI Can Reach ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fwordpress-comment2shell-flaw-can-turn.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEiPBWV1XNsTGB5ImLNRGJTygk0-82k7xTHmuOr7lTivRRDcF83ddu4jLOpdkQYMq7VB3j5SMpA9zBRvM3-SUkDLBhN5-j-Z6UltcTnVfXOxHDzfBYWiw_fRiRefAYa1XSiFu5JMzb06dwqV4PhKaZkPt3vKZFHQjdVFUgbr2B3nOEoFs_qHe6zwGayHM2I\u002Fs1600\u002Fwordpress-comment.jpg","2026-09-22T06:03:14+00:00","2026-09-22T08:00:29.46545+00:00",8,[18,21,24],{"name":19,"type":20},"WordPress","product",{"name":22,"type":23},"XSS","technology",{"name":25,"type":23},"RCE","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":26,"icon":28,"name":29,"slug":30},null,"Vulnerabilities","vulnerabilities",[32,34],{"category":33},{"id":26,"icon":28,"name":29,"slug":30},{"category":35},{"id":36,"icon":28,"name":37,"slug":38},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[40],{"type":41,"value":42,"context":43},"cve","CVE-2026-93485","Comment2Shell vulnerability identifier"]