WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
⚡ WordPress “Comment2Shell” XSS → RCE flaw patched
⚠️ WordPress core flaw lets an anonymous comment embed a hidden script that runs when a logged‑in administrator views the page.
🆔 The issue is tracked as CVE-2026-93485 and dubbed Comment2Shell.
📅 WordPress released a fix in version 7.1.1 on September 17 and urged immediate updates.
📢 Sites still on vulnerable releases risk full server compromise.
Takeaway: Update WordPress to 7.1.1 right away to close the exploit.
---
Source: https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html
