AI Weekly Malaysia

Back to items Summaries

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

ID
27165
Status
summarized
Published
22 Sep 2026, 2:03 PM
Fetched
22 Sep 2026, 8:16 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.0
Created
22 Sep 2026, 8:21 PM
Tags
Audience
developerssaas_founders

What happened

WordPress core vulnerability CVE-2026-93485 ('Comment2Shell'), fixed in version 7.1.1 on September 17, lets an anonymous commenter plant XSS by inserting a line break inside an allowed HTML tag attribute—WordPress's comment reformatting step breaks the tag apart and turns the attacker's text into a live event handler that fires on page load with no click. If a logged-in admin views the affected page, the script can hijack their session to upload a malicious plugin and gain remote code execution on the server. No active exploitation has been observed; CVSS rated 7.1 by Patchstack.

Why it matters

If you run any WordPress site on a version before 7.1.1, update immediately—comment moderation is off by default, so an unapproved anonymous comment can reach the page and the chain requires only that an admin later views it. The XSS-to-RCE escalation via plugin upload is a well-known path, so the real exposure is any WP instance with comments enabled and an admin who browses their own comment sections.

Discussion angle

Walk through the two-step bug: why WordPress's save-time sanitization missed the line-break-in-attribute trick, and how the display-time reformatting turned it into a live handler—then discuss whether your own CMS or comment system has a similar gap between input validation and output rendering.

Top