Cookie Consent by Free Privacy Policy Generator

WordPress Patches Critical Comment2Shell Vulnerability Allowing Anonymous RCE

WordPress released version 7.1.1 on 17 September 2026 to address a critical vulnerability tracked as CVE-2026-93485, known as Comment2Shell. The Hacker News reports that the flaw allowed an anonymous visitor to leave a comment containing a hidden script on a WordPress site. If a logged-in administrator later viewed that comment, the script could execute, potentially allowing the attacker to run code on the server. The vulnerability represents a particularly dangerous escalation path because it requires no authentication and relies on normal administrative behaviour, viewing comments, to trigger the exploit. WordPress has urged all site owners to update immediately.

Why this matters for UK organisations

This is a significant risk for any organisation running WordPress, which remains one of the most widely used content management systems globally, including across UK public sector, education, SME and corporate websites. The attack chain is straightforward: an unauthenticated attacker posts a malicious comment, an administrator reviews it as part of routine moderation, and the site is compromised. The flaw underscores how even mature platforms can harbour critical vulnerabilities in everyday features, and why timely patching and version management remain foundational security disciplines. For organisations running WordPress at scale, this is also a reminder to review who has administrative access, whether comment moderation is appropriately delegated, and how quickly security updates are applied across all instances. The vulnerability also highlights the importance of defence in depth: even if patching is delayed, controls such as limiting administrative access, segregating comment moderation from full site administration, and monitoring for unusual activity can reduce the window of exposure. Organisations that rely on WordPress for customer-facing services, internal knowledge bases or marketing sites should treat this as a high-priority update and use it as an opportunity to review how content management systems are maintained and secured across the estate.

What to review

Confirm that all WordPress instances have been updated to version 7.1.1 or later, and review how quickly security patches are identified, tested and deployed across content management systems, particularly where multiple sites or instances are in use. Check who has administrative access to WordPress sites and whether comment moderation privileges can be delegated to users with lower access levels, reducing the risk that a malicious comment is viewed by a fully privileged administrator. Review how WordPress instances are inventoried and managed, ensuring that all sites, including development, staging and legacy environments, are included in patching programmes. Consider whether monitoring is in place to detect unusual administrative activity, unexpected code changes or signs of compromise, and ensure that backups are current and tested so that recovery is possible if a site is affected. This is also a prompt to review how third-party plugins and themes are managed, as these often introduce additional vulnerabilities and should be kept up to date alongside WordPress core.

Source: The Hacker News

News and blog posts
The US Cybersecurity and Infrastructure Security Agency has added...
Today's brief reflects the practical reality of defending modern organisations:...
The National Cyber Security Centre has published a blog post titled "One does...
WordPress released version 7.1.1 on 17 September 2026 to address a critical...