Update WordPress core to version 7.1.1 or later immediately. Ensure all themes and plugins are kept up to date. As additional mitigation, administrators should consider restricting comment functionality where not required for site operations and monitor for unusual activity in comment sections.
Quick answers
What is CVE-2026-93485?
Update WordPress core to version 7.1.1 or later immediately. Ensure all themes and plugins are kept up to date. As additional mitigation, administrators should consider restricting comment functionality where not required for site operations and monitor for unusual activity in comment sections.
How severe is CVE-2026-93485?
high, CVSS 8.8
Is CVE-2026-93485 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-93485 be mitigated?
Update WordPress core to version 7.1.1 or later immediately. Ensure all themes and plugins are kept up to date. As additional mitigation, administrators should consider restricting comment functionality where not required for site operations and monitor for unusual activity in comment sections.
CVSS
8.8
Vendor
Automattic
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
WordPress Core
Mitigation
Update WordPress core to version 7.1.1 or later immediately. Ensure all themes and plugins are kept up to date. As additional mitigation, administrators should consider restricting comment functionality where not required for site operations and monitor for unusual activity in comment sections.
A stored cross-site scripting vulnerability in WordPress core, tracked as CVE-2026-93485 and dubbed "Comment2Shell," was publicly disclosed and patched on September 17, 2026. The flaw allowed anonymous visitors to inject malicious scripts through comments. When a logged-in administrator subsequently viewed the affected page, the script executed in their browser session, potentially enabling remote code execution on the server. WordPress version 7.1.1 contains the fix.