Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical WordPress Flaw Through Comments Threatens Sites

Critical WordPress Flaw Through Comments Threatens Sites

Posted on September 26, 2026 By CWS

WordPress users are being cautioned to address a significant vulnerability that could allow attackers to execute commands via site comments. This high-severity flaw, identified as CVE-2026-93485, is linked to the wpautop() function of WordPress, leading to potential command execution from anonymous comments. The vulnerability has been resolved in WordPress version 7.1.1, and site administrators are advised to update without delay.

Understanding the Vulnerability

The issue, showcased in the Comment2Shell proof-of-concept, involves a stored cross-site scripting (XSS) vulnerability. This flaw is exploited when a specially crafted comment, appearing harmless, is processed by WordPress. Specifically, a newline embedded within the cite attribute of a blockquote element can bypass initial KSES sanitization and later be transformed into executable JavaScript when rendered.

During rendering, the wpautop() function replaces the newline with an HTML-comment placeholder. A flawed regular expression then misinterprets the closing angle bracket, inserting unintended elements that execute attacker-controlled scripts. If a logged-in administrator views such a comment, it could lead to unauthorized administrative actions, exploiting plugin installations and more.

Proof-of-Concept and Mitigation

The Comment2Shell demonstration by Syed Wajeeh-ul-Hassan Rizvi reveals how an attacker can execute commands, clean up traces, and leave minimal evidence of the breach. The attack requires comments to be enabled and visible, with a logged-in admin viewing the crafted content. Notably, the vulnerability does not require any pre-obtained credentials or accounts.

While blocking comments may reduce exposure, administrators are urged to update to WordPress 7.1.1 or the latest patched version. Regular checks of the wp_comments database for unusual patterns and monitoring suspicious admin activities are recommended. Disabling comments temporarily can also serve as a preventative measure until a patch is applied.

Preventive Actions and Recommendations

WordPress releases affected by this vulnerability range from 4.7 to 7.1.0. The flaw was reported by Rafie Muhammad through WordPress’s secure disclosure process. The Comment2Shell project provides tools for scanning and exploiting this vulnerability, highlighting the need for immediate defensive measures.

Administrators should ensure updates are applied promptly and review any unusual activity in plugin directories. Monitoring wp-comments-post.php and wp-admin/update.php for irregular requests is crucial. Until the issue is fully addressed, vigilance in examining plugin uploads and administrator sessions is advised.

While there have been no reported active exploitations, the availability of the proof-of-concept increases the risk of replication. Organizations must prioritize securing their sites and treating any unexplained comment or plugin activity as potential compromises.

Cyber Security News Tags:admin protection, anonymous comments, comment exploit, CVE-2026-93485, Cybersecurity, patch update, plugin security, site update, Vulnerability, Webshell, website protection, WordPress patch, WordPress security, wpautop flaw, XSS attack

Post navigation

Previous Post: ServiceNow Urges Patching Critical Vulnerabilities
Next Post: Business Emails Exploited for Malware Attacks

Related Posts

Microsoft’s KB5121767 Update Resolves Dell USB-C Issues Microsoft’s KB5121767 Update Resolves Dell USB-C Issues Cyber Security News
Hackers Compromise Coder Registry for Cloud Credential Theft Hackers Compromise Coder Registry for Cloud Credential Theft Cyber Security News
13-year-old Critical Redis RCE Vulnerability Let Attackers Gain Full Access to Host System 13-year-old Critical Redis RCE Vulnerability Let Attackers Gain Full Access to Host System Cyber Security News
ClayRat Android Malware Steals SMS Messages, Call Logs and Capture Victim Photos ClayRat Android Malware Steals SMS Messages, Call Logs and Capture Victim Photos Cyber Security News
Microsoft VS Code Remote-SSH Extension Hacked to Execute Malicious Code on Developer’s Machine Microsoft VS Code Remote-SSH Extension Hacked to Execute Malicious Code on Developer’s Machine Cyber Security News
Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Business Emails Exploited for Malware Attacks
  • Critical WordPress Flaw Through Comments Threatens Sites
  • ServiceNow Urges Patching Critical Vulnerabilities
  • TWEAKOS Malware Exploits Telegram for Account Theft
  • Salmon Launches EVI to Secure AI and Autonomous Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Business Emails Exploited for Malware Attacks
  • Critical WordPress Flaw Through Comments Threatens Sites
  • ServiceNow Urges Patching Critical Vulnerabilities
  • TWEAKOS Malware Exploits Telegram for Account Theft
  • Salmon Launches EVI to Secure AI and Autonomous Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark