WordPress shipped a fix for a stored cross-site-scripting bug buried in its own comment-rendering code, a flaw serious enough to be chained into full remote code execution on any site that still allows comments. The vulnerability lived inside wpautop(), the PHP function WordPress uses to turn a visitor's plain-text comment into formatted HTML, and it required nothing more than an anonymous comment to trigger.
Orca Security's research team tracked the flaw as CVE-2026-93485, rated 7.1 on the CVSS scale, and detailed how it escalates from an anonymous comment to full server control. A comment containing a deliberately misplaced greater-than character confuses wpautop()'s tag-parsing logic, splitting an HTML tag apart and relocating attacker-controlled text into a spot the browser treats as live, executable script. Nothing fires until an administrator opens the page holding that comment; at that point the injected script runs inside the admin's own logged-in session, installs a plugin that plants a web shell, and hands the attacker a foothold on the server without a password and without the admin clicking anything. Orca calls the chain Comment2Shell for that final step.
The exposure is broad by default. WordPress Core versions 4.7 through 7.1.0, the vast majority of installations in use, are affected, and comment moderation does not fully close the door: a visitor who has had one comment approved before is auto-approved on every later comment, and plenty of site owners turn moderation off altogether. Orca rates the attack complexity low, found no public proof-of-concept, and says there is no evidence of active exploitation; the flaw is not on CISA's Known Exploited Vulnerabilities (KEV) catalog.
WordPress's own security team confirms that timeline. Version 7.1.1, one of eleven security fixes the project shipped on September 17, closes a matching stored cross-site-scripting bug in wpautop() that an unauthenticated visitor can trigger through a comment, subject to approval, essentially the same flaw and the same fix Orca is pointing to. Sites with automatic background updates already have the patch; everyone else should update to 7.1.1, or the matching backport for their branch, right away. In the meantime, turn off comments, switch moderation to manual approval, add WAF rules that filter comment payloads, and check for any plugin nobody remembers installing.
That release was not the month's last word on WordPress security. The same day Orca published its research, WordPress pushed out version 7.1.2 to close a second, unrelated critical flaw, a local file inclusion bug in template resolution that can also lead to remote code execution under the right server and theme conditions. A site still running anything older than 7.1.2 is carrying two separate holes at once.












