WordPress administrators are being urged to patch a high-severity core vulnerability that can turn an anonymous comment into server-side command execution. Tracked as CVE-2026-93485 and demonstrated by the Comment2Shell proof-of-concept, the flaw is an unauthenticated stored cross-site scripting issue in WordPress’s wpautop() formatting function. WordPress fixed the vulnerability in version 7.1.1 and advised site owners […]
Read the original article:
