Skip to content

CVE-2026-93485

CVE

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
September 22, 2026
Last Seen
September 22, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical vulnerability in WordPress, tracked as CVE-2026-93485, allows unauthenticated users to execute remote code on servers through a crafted comment. This flaw, dubbed 'Comment2Shell,' enables attackers to insert malicious scripts that execute when a logged-in administrator views the comment....

Public Exploits

Checking GitHub for proof-of-concept code…