WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
Summary
A critical vulnerability in WordPress, dubbed 'Comment2Shell', allowed anonymous users to inject malicious scripts via comments that could be executed as Remote Code Execution (RCE) by logged-in administrators. WordPress has released version 7.1.1 to address this flaw, identified as CVE-2026-93485.
IFF Assessment
FOE
The discovery of an RCE vulnerability that can be exploited by anonymous users through comments poses a significant threat to WordPress websites.
Severity
7.1
High
Defender Context
This vulnerability highlights the importance of promptly patching WordPress sites and the risks associated with comment functionality if not properly secured. Defenders should be aware of such injection flaws that can escalate from XSS to RCE, especially when administrative privileges are involved.