1.
Comment2Shell is a dependency-free Python exploit kit for WordPress CVE-2026-93485 (CVSS 7.1), chaining pre-auth stored XSS in wpautop() to zero-click RCE when an admin views the infected post.
Why it matters: Affects all WordPress installations from version 4.7.0 through 7.1.0 without requiring credentials or interaction beyond opening a post. Administrators should verify upgrading to 7.1.1 or backported releases, and monitor server logs for suspicious comment payloads and unexpected plugin uploads.
Skip to content