Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.
← back | CVE Intelligence

CVE-2026-93485 [High]

Curated 2 security research writeups, vulnerability advisories and exploitation analyses for CVE-2026-93485.

Vendor
WordPress
Product
WordPress
Affected versions
4.7.0 - 7.1.0
CVSS
7.1
Coverage Span
2026-09-21 → 2026-09-25
Reports
2 related reports

Associated Reports & Timeline

1.
github.com | tool | | original ↗ | #bug-bounty | #rce | #zero-day | #wordpress
Comment2Shell is a dependency-free Python exploit kit for WordPress CVE-2026-93485 (CVSS 7.1), chaining pre-auth stored XSS in wpautop() to zero-click RCE when an admin views the infected post.
Why it matters: Affects all WordPress installations from version 4.7.0 through 7.1.0 without requiring credentials or interaction beyond opening a post. Administrators should verify upgrading to 7.1.1 or backported releases, and monitor server logs for suspicious comment payloads and unexpected plugin uploads.