CVE-2026-93485 with a CVSS score of 7.1, a vulnerability known as Comment2Shell in WordPress core allowed an anonymous visitor to leave a comment containing a hidden script that could run code on the site's server when opened by a logged-in administrator. The flaw sat in the gap between WordPress's HTML checking and reformatting steps, where it placed a line break inside the attribute of an allowed HTML tag in the comment, breaking the tag apart and moving the attacker's text into a spot where the browser treated it as a live event handler. This handler ran automatically as the page loaded, with no click required, allowing the script to use the administrator's session to upload a plugin containing a web shell, enabling an attacker to gain control of the server. The vulnerability was exploitable only subject to comment approval but could be bypassed by placing the comment on the page first and then exploiting it when opened by an administrator. The flaw was addressed through a WordPress security release.
We recommend you to update WordPress to version 7.1.2 or later.[/subscribe_to_unlock_form]
CVE-2026-93485 with a CVSS score of 7.1, a vulnerability known as Comment2Shell in WordPress core allowed an anonymous visitor to leave a comment containing a hidden script that could run code on the site's server when opened by a logged-in administrator. The flaw sat in the gap between WordPress's HTML checking and reformatting steps, where it placed a line break inside the attribute of an allowed HTML tag in the comment, breaking the tag apart and moving the attacker's text into a spot where the browser treated it as a live event handler. This handler ran automatically as the page loaded, with no click required, allowing the script to use the administrator's session to upload a plugin containing a web shell, enabling an attacker to gain control of the server. The vulnerability was exploitable only subject to comment approval but could be bypassed by placing the comment on the page first and then exploiting it when opened by an administrator. The flaw was addressed through a WordPress security release.
We recommend you to update WordPress to version 7.1.2 or later.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]