WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site’s server.

WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed “Comment2Shell,” on September 17 in version 7.1.1 and told site owners to update right away. There is

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. “TWINLOOT is a modular,

AI: The ROI Runway Could Be Long Outside the Tech Sector

AI: The ROI Runway Could Be Long Outside the Tech Sector Source: Hacker News

Strait of Hormuz Live Traffic Tracking

Strait of Hormuz Live Traffic Tracking Source: Hacker News