Search
Find merged stories by title or summary.
Vulnerabilities & Patches
Emerging1 src
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and called "Comment2Shell," on September 17 in version 7. 1. 1 and told site owners to update right away. There is
Vulnerabilities & Patches
Emerging1 src
NVD-CVE-2026-93485 - National Institute of Standards and Technology (.gov)
NVD-CVE-2026-93485 National Institute of Standards and Technology (.gov)
You've reached the end of current stories for this search.
