Comment2Shell CVE-2026-93485: An Anonymous Comment That Reaches the Server
WordPress released version 7.1.1 on 17 September 2026 and fixed a flaw it named Comment2Shell, tracked as CVE-2026-93485. Patchstack assigned a CVSS score of 7.1. The researcher who reported it, Rafie Muhammad, published a full exploitation walkthrough on 21 September 2026. There is no evidence that the flaw has been used in real attacks, and it had not been added to the United States exploited-vulnerabilities catalog at the time of writing.
Where the gap sits
WordPress sanitises dangerous HTML when a comment is saved and reformats comment content again when the page is rendered. The flaw lives in the space between those two steps. An attacker inserts a newline character inside an attribute of an HTML tag that comments are permitted to use. During render formatting, one step splits that tag, and the inserted content moves to a position the browser reads as an active event handler. The handler runs on page load with no click required and inherits the visiting user's access to the site.
Reaching code execution on the server needs one more condition: a logged-in administrator has to open the page that holds the malicious comment. In that session the injected script can upload a plugin containing a web shell, which is a known path to server control once an administrator's browser is executing attacker-supplied JavaScript.
The moderation assumption
WordPress states that the flaw is exploitable only when comment moderation is enabled for the comment in question. Patchstack's position is blunter: comment moderation is not a security control. Moderation is off by default in WordPress, and the restriction that sends a first-time commenter to the queue can be bypassed, so a comment can appear without any human review. Any deployment that treats an empty queue as evidence that no hostile comment exists is relying on an assumption the product does not guarantee.
Scope and fixes
The affected range runs from WordPress 4.7 through 7.1. Fixed releases per branch are 7.1.1 on the 7.1 line, 7.0.5 on 7.0, 6.9.8 on 6.9, and updated releases on older branches going back to 4.7.36. The same release also addressed a separate theme-preview flaw reported by Pwn.ai Research and named Click2Shell, which requires a logged-in administrator who previously visited a prepared site in the same browser session.
Remediation
- Update to the fixed release for the branch in use. Updating closes the flaw but does not undo anything an attacker already achieved, so a site that may have been targeted also needs a file and plugin audit.
- If updating is not immediately possible, turn off comments on individual posts or across the site to break the path, and deploy a web application firewall rule or a security plugin that filters the crafted comment.
- Review the plugin and theme directories for entries that no administrator installed, and check for unexpected administrative users.
- Treat comment moderation settings as a user-experience choice, not as a boundary, and stop treating the moderation queue as a record of what is pending on the site.
References
- FreeBuf report on Comment2Shell: https://m.freebuf.com/news/502532.html
- IT之家 report on the WordPress 7.1.1 release: https://www.ithome.com/1/004/358.htm
- CISA Known Exploited Vulnerabilities catalog, used to check exploitation status: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Top comments (0)