Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Comment2Shell: Zero-Click Pre-Auth RCE Exploit Kit for WordPress (CVE-2026-93485)

Summary

Comment2Shell is a dependency-free Python exploit kit for WordPress CVE-2026-93485 (CVSS 7.1), chaining pre-auth stored XSS in wpautop() to zero-click RCE when an admin views the infected post.

Why it matters

Affects all WordPress installations from version 4.7.0 through 7.1.0 without requiring credentials or interaction beyond opening a post. Administrators should verify upgrading to 7.1.1 or backported releases, and monitor server logs for suspicious comment payloads and unexpected plugin uploads.
CVE
CVE-2026-93485
Vendor
WordPress
Product
WordPress
Affected versions
4.7.0 - 7.1.0
CVSS
7.1
Published
Collected

original ↗