Comment2Shell: Zero-Click Pre-Auth RCE Exploit Kit for WordPress (CVE-2026-93485)
github.com | tool | CVE-2026-93485 | #bug-bounty | #rce | #zero-day | #wordpress | #xss | #red-team | #poc | #exploit-kit | #webshell | #wpautop | #cve-2026-93485
Summary
Comment2Shell is a dependency-free Python exploit kit for WordPress CVE-2026-93485 (CVSS 7.1), chaining pre-auth stored XSS in wpautop() to zero-click RCE when an admin views the infected post.
Why it matters
Affects all WordPress installations from version 4.7.0 through 7.1.0 without requiring credentials or interaction beyond opening a post. Administrators should verify upgrading to 7.1.1 or backported releases, and monitor server logs for suspicious comment payloads and unexpected plugin uploads.
- CVE
- CVE-2026-93485
- Vendor
- WordPress
- Product
- WordPress
- Affected versions
- 4.7.0 - 7.1.0
- CVSS
- 7.1
- Published
- Collected
Skip to content