HackerFeeds

CyberSecurity News

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

The Hacker News
· September 22, 2026

AI summary

A vulnerability in WordPress core allowed an anonymous visitor to leave a comment that embedded a hidden script on the page. If an administrator later viewed the page while logged in, the script could execute code on the site's server, potentially leading to remote code execution. The flaw, known as Comment2Shell, was addressed by WordPress in version 7.1.1, released on September 17. WordPress has advised site owners to update immediately to fix the issue, which is tracked as CVE-2026-93485. The vulnerability enabled an escalation from cross-site scripting to remote code execution via an admin session. WordPress has taken steps to mitigate the flaw by releasing an updated version.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.