A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away.
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
About this summary. This is a short, independently written summary of an article first published by The Hacker News. Cyber Security News did not report or verify the underlying story. Read the original: https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html

Source attribution: headline and facts are from The Hacker News (thehackernews.com). Summary method: excerpt of the source description. See our source attribution policy.




