Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Patch Fixes Critical Comment2Shell Vulnerability

WordPress Patch Fixes Critical Comment2Shell Vulnerability

Posted on September 22, 2026 By CWS

The WordPress platform recently addressed a significant security vulnerability known as Comment2Shell, which allowed attackers to exploit site comments to execute malicious code. The issue, identified as CVE-2026-93485, could enable anonymous users to insert harmful scripts via comments, which would execute if a page was later accessed by an administrator. The patch for this flaw was released on September 17, 2026, with version 7.1.1 of WordPress.

Understanding the Comment2Shell Flaw

The vulnerability was discovered by security researcher Rafie Muhammad. It occurred due to a gap in how WordPress processed comments. When a comment containing a specially crafted HTML tag was saved, a flaw in the reformatting process allowed it to execute scripts in a visitor’s browser. This flaw, if exploited, could elevate an attacker’s privileges, particularly if accessed by a logged-in administrator.

The flaw was rated 7.1 out of 10 on the CVSS scale by Patchstack, indicating a high severity level. However, there have been no reported instances of the flaw being actively used in attacks. It is also not listed among the U.S. government’s known exploited vulnerabilities.

Mitigating the Risk

To safeguard against potential exploitation, site owners are strongly advised to update to WordPress version 7.1.1 or the latest available security patch for their branch. The affected versions span from 4.7 to 7.1. While updating resolves the issue, administrators should also review their sites for any unauthorized plugins or files.

For sites unable to update immediately, disabling comments site-wide or implementing a web application firewall could provide temporary protection. WordPress emphasized that while the flaw is exploitable only with comment approval, default settings often allow comments without manual approval, underscoring the need for vigilance.

Broader Security Concerns

This patch is part of a broader security update that addressed 11 vulnerabilities, including another significant issue termed Click2Shell. This separate flaw involved the potential for a crafted link to install a theme and execute server-side code, also requiring administrative access to trigger.

WordPress has faced similar security challenges throughout the year. Notably, the wp2shell bug discovered in July allowed code execution without login credentials, subsequently recognized by U.S. authorities as actively exploited. Additionally, an August vulnerability enabled code execution via the login page.

Ensuring that WordPress sites are regularly updated and maintained is crucial to protecting against such vulnerabilities. Administrators should remain informed and proactive in applying security patches to mitigate risks.

The Hacker News Tags:admin session, Comment2Shell, CVE-2026-93485, Exploit, Patchstack, Rafie Muhammad, RCE, security flaw, security patch, Update, Vulnerability, web security, web shell, WordPress, XSS

Post navigation

Previous Post: Hidden Setting in Muse AI Poses Security Threat
Next Post: SideCopy Shifts Focus to Indian Academia with ReverseRAT

Related Posts

DCloud Uni-App Framework Fuels Global Crypto Scams DCloud Uni-App Framework Fuels Global Crypto Scams The Hacker News
WhatsApp Rolls Out Lockdown-Style Security Mode to Protect Targeted Users From Spyware WhatsApp Rolls Out Lockdown-Style Security Mode to Protect Targeted Users From Spyware The Hacker News
Why Runtime Visibility Must Take Center Stage Why Runtime Visibility Must Take Center Stage The Hacker News
Microsoft Identifies Three Salesforce Threat Vectors Microsoft Identifies Three Salesforce Threat Vectors The Hacker News
CISA Warns of Active n8n Vulnerability Exploitation CISA Warns of Active n8n Vulnerability Exploitation The Hacker News
Langflow Security Flaw Enables Unauthenticated Access Langflow Security Flaw Enables Unauthenticated Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Japan Dismantles North Korean Laptop Farm Amid Global Cyber Scheme
  • SideCopy Shifts Focus to Indian Academia with ReverseRAT
  • WordPress Patch Fixes Critical Comment2Shell Vulnerability
  • Hidden Setting in Muse AI Poses Security Threat
  • Hackers Exploit Microsoft Teams for Password Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Japan Dismantles North Korean Laptop Farm Amid Global Cyber Scheme
  • SideCopy Shifts Focus to Indian Academia with ReverseRAT
  • WordPress Patch Fixes Critical Comment2Shell Vulnerability
  • Hidden Setting in Muse AI Poses Security Threat
  • Hackers Exploit Microsoft Teams for Password Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark