WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
- ID
- 27165
- Status
- summarized
- Published
- 22 Sep 2026, 2:03 PM
- Fetched
- 22 Sep 2026, 8:16 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.0
- Created
- 22 Sep 2026, 8:21 PM
- Tags
- Audience
- developerssaas_founders
What happened
WordPress core vulnerability CVE-2026-93485 ('Comment2Shell'), fixed in version 7.1.1 on September 17, lets an anonymous commenter plant XSS by inserting a line break inside an allowed HTML tag attribute—WordPress's comment reformatting step breaks the tag apart and turns the attacker's text into a live event handler that fires on page load with no click. If a logged-in admin views the affected page, the script can hijack their session to upload a malicious plugin and gain remote code execution on the server. No active exploitation has been observed; CVSS rated 7.1 by Patchstack.
Why it matters
If you run any WordPress site on a version before 7.1.1, update immediately—comment moderation is off by default, so an unapproved anonymous comment can reach the page and the chain requires only that an admin later views it. The XSS-to-RCE escalation via plugin upload is a well-known path, so the real exposure is any WP instance with comments enabled and an admin who browses their own comment sections.
Discussion angle
Walk through the two-step bug: why WordPress's save-time sanitization missed the line-break-in-attribute trick, and how the display-time reformatting turned it into a live handler—then discuss whether your own CMS or comment system has a similar gap between input validation and output rendering.