Skip to content
WordPress Comment2Shell Vulnerability Allows RCE via Anonymous Comments

WordPress Comment2Shell Vulnerability Allows RCE via Anonymous Comments

First seen 22 Sep 2026, 09:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 10:29 UTC
  • CVE-2026-93485 allows RCE via anonymous comments on WordPress sites.
  • The vulnerability affects all versions from 4.7 to 7.1, requiring immediate updates.
  • No active exploitation has been reported, but the risk remains significant.

A critical vulnerability in WordPress, tracked as CVE-2026-93485, allows unauthenticated users to execute remote code on servers through a crafted comment. This flaw, dubbed 'Comment2Shell,' enables attackers to insert malicious scripts that execute when a logged-in administrator views the comment. The vulnerability arises from improper handling of HTML in the wpautop() function, which transforms line breaks into paragraphs. WordPress released a patch in version 7.1.1 on September 17, 2026, addressing this issue. The flaw affects all WordPress versions from 4.7 onward, with the patch backported to older versions. Although no active exploitation has been reported, site owners are urged to update immediately. The vulnerability has a CVSS score of 7.1, indicating a high severity level. Rafie Muhammad, the researcher who discovered the flaw, reported it through the WordPress bug bounty program.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-17
CVE-2026-63030 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-17
CVE-2026-60137 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-07
CVE-2026-64638 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-17
WordPress 7.1.1 released
Version 7.1.1 includes a fix for CVE-2026-93485, addressing the Comment2Shell vulnerability.
Patchstack
2026-09-18
CVE-2026-93485 published
The vulnerability was officially published, detailing the unauthenticated stored XSS flaw in WordPress.
The Hacker News
2026-09-21
Researcher details exploit chain
Rafie Muhammad published a write-up explaining the exploit chain for CVE-2026-93485.
Cyberkendra

More articles in this cluster (5)

Following this threat?

Track CVE-2026-93485 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed