WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
🤖 Intelligence Artificielle
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away. There is
📖 Cet article provient d'une source externe.
🔗 Lire l'article complet sur la source →64 mots extraits · Source originale
🔥 OFFRE PARTENAIRE
G-tab PAD10 PRO NEO Tablet, 10.1 inch 1280×800 Incell Display, Allwinner A537 Octa-Core 2.0GHz, 6GB RAM 128GB ROM, Android 15, 2.4GHz / 5GHz Dual Band WiFi, Bluetooth 5.0, 5MP + 13MP Camera, 6580mAh Battery, Type-C OTG
🔥 G-tab PAD10 PRO NEO Tablet, 10.1 inch 1280×800 Incell Display, Allwinner A537 Octa-Core 2.0GHz, 6GB RAM 128GB ROM, Android 15, 2.4GHz / 5GHz Dual Band WiFi, Bluetooth 5.0, 5MP + 13MP Camera, 6580mAh Battery, Type-C OTG - Une offre exceptionnelle à ne pas manquer ! Cliquez pour découvrir.
✅ Consultez les photos supplémentaires.
✅ Découvrez toutes les caractéristiques.
✅ Vérifiez la disponibilité actuelle.
✅ Consultez les avis des acheteurs.
✅ Découvrez toutes les caractéristiques.
✅ Vérifiez la disponibilité actuelle.
✅ Consultez les avis des acheteurs.