Patch released WordPress rce web-app
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
CVE Tools coverage
WordPress has fixed CVE-2026-93485, known as Comment2Shell, an issue that could let an anonymous commenter inject script into a page. If a logged-in administrator viewed the affected comment, the script could abuse that session to upload a malicious plugin and execute code on the server. The flaw affects WordPress 4.7 through 7.1; update to WordPress 7.1.1 or the fixed release for the supported branch. No exploitation has been reported.