Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2026-93485] Comment2XSS: Zero-Click Pre-Auth XSS to Potential RCE in WordPress Core

Summary

An unauthenticated stored XSS (CVE-2026-93485) in WordPress core's wpautop() turns crafted comments into zero-click XSS, escalating to RCE via the admin session. Fixed in 7.1.1, backported to 4.7.36.
CVE
CVE-2026-93485
Published
Collected

original ↗