A severe vulnerability discovered in WordPress core allows unauthenticated website visitors to inject malicious scripts through comment fields. Tracked as CVE-2026-93485 and named Comment2 Shell, this security hole creates a direct pathway from simple cross-site scripting to full remote code execution on the underlying server.
The attack vector relies on an anonymous user submitting a specifically crafted comment containing a hidden script. When an authenticated site administrator subsequently reviews or opens the affected page, the malicious code executes within the administrative context. This unauthorized execution can compromise the entire web server, giving attackers complete control over the hosting environment.
The vulnerability bridges a gap between frontend user input and backend server privileges. Because comment systems must accept text from the public, they represent a traditional target for injection attacks.
Security researchers found that improper sanitization allowed the injected script to persist within the database. When loaded in the browser of a high-privileged user, the payload leverages existing administrative privileges to breach server-level defenses.
Prompt patch management remains the primary defense against this critical vulnerability. WordPress developers have released a formal security update addressing CVE-2026-93485 across all supported versions.
Website operators should immediately verify that their installations are running the latest patched software. Neglecting this update leaves servers exposed to automated exploitation scripts targeting the Comment2 Shell vector.
Q: Which component of WordPress is affected? A: The vulnerability exists within the WordPress core comment handling system, rather than in a third-party plugin or theme.