Thehackernews iconThehackernewsSep 22, 2026

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and called "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away.

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

Share this story

Send the public story page.

Useful takeaways from this story.

If a logged-in administrator later opened that page, the script could run code on the site's server.

WordPress fixed the flaw, tracked as CVE-2026-93485 and called "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and called "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app