Back to all news
Security

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

The Hacker News·September 22, 2026·1 min read
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

A WordPress core flaw, tracked as CVE-2026-93485 and dubbed 'Comment2Shell,' allowed an anonymous comment to plant a hidden script that could execute code on the server when an admin viewed the page. WordPress fixed it on September 17 in version 7.1.1 and urged site owners to update immediately.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store