WordPress Remote Code Execution Vulnerabilities “Click2Shell” (CVE-Unknown) and “Comment2Shell” (CVE-2026-93485)

Two serious vulnerabilities, known as “Click2Shell” (with CVE-Unknown) and “Comment2Shell” (with CVE-2026-93485), have been identified in WordPress Core. The vulnerabilities could allow an unauthenticated attacker to leverage a logged-in WordPress administrator’s session and ultimately execute arbitrary PHP code on the affected server. Successful exploitation could result in full compromise of the affected website.

WordPress has released security updates to address the vulnerabilities. System owners are strongly recommended to verify their installed WordPress version and update to the latest version immediately.

 

Vulnerability

  • WordPress Pre-Authentication Remote Code Execution Vulnerability “Click2Shell” (CVE-Unknown)
    • An attacker could create a specially crafted URL that causes the browser of a logged-in WordPress administrator to automatically install and preview an attacker-selected theme from the official WordPress.org theme directory.
    • The administrator does not need to click Install or Activate.
    • When chained with a separate vulnerability in the installed theme, the attacker could execute arbitrary PHP code under the WordPress server account.
    • The installed theme may remain inactive throughout the attack, meaning the website’s appearance may not change and the compromise may not be immediately noticeable.

    • Public Proof-of-Concept (PoC) is available.

 

  • WordPress Stored Cross-Site Scripting to Remote Code Execution Vulnerability “Comment2Shell” (CVE-2026-93485)
    • An unauthenticated attacker could submit a specially crafted comment that exploits a stored cross-site scripting vulnerability in the WordPress comment-rendering process.
    • When the malicious comment is displayed, the injected script could execute automatically in the visitor’s browser.
    • If a logged-in WordPress administrator views the affected page, the malicious script could misuse the administrator’s authenticated session to perform privileged actions.
    • The attack could be escalated to remote code execution, including the installation of a malicious plugin or web shell on the affected server.
    • Websites using block themes are affected. Websites using classic themes may also be affected if posts or pages contain comment blocks.
    • The risk is higher for websites that automatically publish comments or do not require all comments to be manually approved.

Severity Level

  • High to Critical

Affected Versions

  • WordPress Core versions prior to 7.1.1
  • Older supported WordPress branches may also be affected unless the corresponding security backport has been applied.

Remediation

  • Update WordPress Core immediately:
    • Upgrade affected installations to WordPress 7.1.1 or later.
    • For installations remaining on an older maintained branch, apply the corresponding security release provided by WordPress.
  • Verify automatic updates:
    • System owners should verify the currently installed version instead of assuming that the update has been completed successfully.
  • Update and review installed themes:
    • Update all installed themes to their latest versions, including inactive themes.
    • Remove unused, outdated, or untrusted themes from the server instead of merely deactivating them.
  • Avoid opening untrusted links while logged in as an administrator:
    • WordPress administrators should avoid accessing links received through unsolicited emails, instant messages, websites, or other untrusted sources while an active WordPress administrator session is present.
    • Log out when administrative access is no longer required.
  • Perform a post-update security review.
  • Back up the website before updating.

 

Reference

 

 

 

Published on: 21 September 2026