WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site’s server.

WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed “Comment2Shell,” on September 17 in version 7.1.1 and told site owners to update right away. There is

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

New Avalon Malware Framework Packs CrownX Ransomware Capabilities Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that’s distributed by means of a multi-stage phishing chain capable

Attack Update: Top 5 Attack-IPs auf doode.info – 31.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 34.68.39.29 — 668 requests (recent log) 34.70.129.79 — 483 requests (recent log) 89.167.35.212 — 478 requests (recent

Tailscale Traces Database Corruption to 16y/o SQLite WAL-Reset Bug

Tailscale Traces Database Corruption to 16y/o SQLite WAL-Reset Bug Source: Hacker News