WordPress: WordPress Comment2Shell Vulnerability Lets Hackers Take Over Sites Through Comments

WordPress: WordPress Comment2Shell Vulnerability Lets Hackers Take Over Sites Through Comments

High-Severity WordPress Vulnerability Enables Remote Code Execution via Malicious Comments

A critical vulnerability in WordPress, tracked as CVE-2026-93485 (CVSS 7.1), allows unauthenticated attackers to execute server-side commands by exploiting a stored cross-site scripting (XSS) flaw in the platform’s wpautop() formatting function. The issue was patched in WordPress 7.1.1, with fixes backported to versions as early as 4.7.36.

The flaw, demonstrated by the Comment2Shell proof-of-concept, enables attackers to embed malicious payloads in seemingly harmless comments. By crafting a newline within the cite attribute of a blockquote element, the exploit bypasses initial sanitization via WordPress’s KSES filter. During rendering, wpautop() incorrectly processes the payload, injecting attacker-controlled onfocus and autofocus attributes that trigger JavaScript execution when viewed.

If an administrator loads the infected post, the XSS payload gains privileged access, allowing it to:

  • Retrieve the plugin-installation nonce
  • Construct and upload a webshell disguised as a plugin
  • Execute arbitrary commands before self-deleting to minimize detection

Exploitation requires comments to be enabled, anonymous submissions allowed, and the malicious comment to be visible (e.g., auto-approved or manually published). While block themes are most vulnerable, classic themes may also be affected under certain conditions. Comment moderation can mitigate immediate risks but should not be relied upon as a security control.

The vulnerability affects WordPress versions 4.7 through 7.1.0, with patches available for all supported branches. Rafie Muhammad of Awesome Motive reported the underlying issue, while the Comment2Shell project provides tools for detection, including a Python scanner, Nuclei template, and IOC checker.

Though no active exploitation was reported at disclosure, the public proof-of-concept lowers the barrier for attacks. Defenders are advised to:

  • Upgrade to WordPress 7.1.1 or the latest patched version
  • Audit wp_comments for suspicious blockquote, cite, onfocus, or autofocus entries
  • Monitor wp-comments-post.php and wp-admin/update.php for unusual activity
  • Inspect wp-content/plugins for unauthorized PHP files

Temporary mitigation includes disabling comments until patches are applied. Organizations should treat unexpected plugin uploads or comment anomalies as potential compromise indicators.

Source: https://cybersecuritynews.com/wordpress-comment2shell-vulnerability/

WordPress cybersecurity rating report: https://www.rankiteo.com/company/wordpress

"id": "WOR1790346574",
"linkid": "wordpress",
"type": "Vulnerability",
"date": "1/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Various (all industries using WordPress)',
                        'location': 'Global',
                        'type': 'Websites'}],
 'attack_vector': 'Stored Cross-Site Scripting (XSS) via malicious comments',
 'data_breach': {'file_types_exposed': 'PHP (webshells)'},
 'description': 'A critical vulnerability in WordPress (CVE-2026-93485, CVSS '
                '7.1) allows unauthenticated attackers to execute server-side '
                'commands by exploiting a stored XSS flaw in the `wpautop()` '
                'formatting function. The flaw enables attackers to embed '
                'malicious payloads in comments, bypassing sanitization via '
                'the KSES filter. If an administrator views the infected post, '
                'the payload retrieves a plugin-installation nonce, uploads a '
                'webshell disguised as a plugin, and executes arbitrary '
                'commands before self-deleting.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'unauthorized access or data breaches',
            'operational_impact': 'Arbitrary command execution, potential full '
                                  'system compromise',
            'systems_affected': 'WordPress websites (versions 4.7 through '
                                '7.1.0)'},
 'initial_access_broker': {'backdoors_established': 'Webshells disguised as '
                                                    'plugins',
                           'entry_point': 'Malicious comments via '
                                          '`wp-comments-post.php`',
                           'high_value_targets': 'Administrator accounts'},
 'lessons_learned': 'Comment moderation is not a sufficient security control; '
                    'regular patching and monitoring of plugin directories are '
                    'critical. Public proof-of-concept exploits lower the '
                    'barrier for attacks, necessitating proactive defenses.',
 'post_incident_analysis': {'corrective_actions': 'Patch the `wpautop()` '
                                                  'function to properly '
                                                  'sanitize `cite` attributes '
                                                  'and newline characters in '
                                                  'comments',
                            'root_causes': 'Insufficient sanitization in '
                                           "WordPress's `wpautop()` function, "
                                           'allowing XSS payloads to bypass '
                                           'KSES filter via crafted '
                                           '`blockquote` elements'},
 'recommendations': ['Upgrade to WordPress 7.1.1 or the latest patched version '
                     'immediately',
                     'Audit `wp_comments` for suspicious `blockquote`, `cite`, '
                     '`onfocus`, or `autofocus` entries',
                     'Monitor `wp-comments-post.php` and `wp-admin/update.php` '
                     'for unusual activity',
                     'Inspect `wp-content/plugins` for unauthorized PHP files',
                     'Disable comments temporarily if patches cannot be '
                     'applied immediately',
                     'Treat unexpected plugin uploads or comment anomalies as '
                     'potential compromise indicators'],
 'references': [{'source': 'Awesome Motive (Rafie Muhammad)'},
                {'source': 'Comment2Shell Proof-of-Concept'}],
 'response': {'containment_measures': 'Upgrade to WordPress 7.1.1 or latest '
                                      'patched version, disable comments '
                                      'temporarily, audit `wp_comments` for '
                                      'suspicious entries',
              'enhanced_monitoring': 'Monitor for unusual activity in comment '
                                     'submissions and plugin uploads',
              'remediation_measures': 'Apply patches, monitor '
                                      '`wp-comments-post.php` and '
                                      '`wp-admin/update.php` for unusual '
                                      'activity, inspect `wp-content/plugins` '
                                      'for unauthorized PHP files'},
 'title': 'High-Severity WordPress Vulnerability Enables Remote Code Execution '
          'via Malicious Comments',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': 'CVE-2026-93485 (WordPress `wpautop()` formatting '
                            'function flaw)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.