WordPress Remote Code Execution Vulnerabilities “Click2Shell” (CVE-Unknown) and “Comment2Shell” (CVE-2026-93485)
Two serious vulnerabilities, known as “Click2Shell” (with CVE-Unknown) and “Comment2Shell” (with CVE-2026-93485), have been identified in WordPress Core. The vulnerabilities could allow an unauthenticated attacker to leverage a logged-in WordPress administrator’s session and ultimately execute arbitrary PHP code on the affected server. Successful exploitation could result in full compromise of the affected website.
WordPress has released security updates to address the vulnerabilities. System owners are strongly recommended to verify their installed WordPress version and update to the latest version immediately.
An attacker could create a specially crafted URL that causes the browser of a logged-in WordPress administrator to automatically install and preview an attacker-selected theme from the official WordPress.org theme directory.
The administrator does not need to click Install or Activate.
When chained with a separate vulnerability in the installed theme, the attacker could execute arbitrary PHP code under the WordPress server account.
The installed theme may remain inactive throughout the attack, meaning the website’s appearance may not change and the compromise may not be immediately noticeable.
An unauthenticated attacker could submit a specially crafted comment that exploits a stored cross-site scripting vulnerability in the WordPress comment-rendering process.
When the malicious comment is displayed, the injected script could execute automatically in the visitor’s browser.
If a logged-in WordPress administrator views the affected page, the malicious script could misuse the administrator’s authenticated session to perform privileged actions.
The attack could be escalated to remote code execution, including the installation of a malicious plugin or web shell on the affected server.
Websites using block themes are affected. Websites using classic themes may also be affected if posts or pages contain comment blocks.
The risk is higher for websites that automatically publish comments or do not require all comments to be manually approved.
Severity Level
High to Critical
Affected Versions
WordPress Core versions prior to 7.1.1
Older supported WordPress branches may also be affected unless the corresponding security backport has been applied.
Remediation
Update WordPress Core immediately:
Upgrade affected installations to WordPress 7.1.1 or later.
For installations remaining on an older maintained branch, apply the corresponding security release provided by WordPress.
Verify automatic updates:
System owners should verify the currently installed version instead of assuming that the update has been completed successfully.
Update and review installed themes:
Update all installed themes to their latest versions, including inactive themes.
Remove unused, outdated, or untrusted themes from the server instead of merely deactivating them.
Avoid opening untrusted links while logged in as an administrator:
WordPress administrators should avoid accessing links received through unsolicited emails, instant messages, websites, or other untrusted sources while an active WordPress administrator session is present.
Log out when administrative access is no longer required.
This website uses Cookies, including Cookies from Google Analytics, to ensure you get the best browsing experience. If you “Continue” to use this site, you consent to the use of Cookies. Read more about Cookies
This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
Cookie
Duration
Description
cookielawinfo-checkbox-analytics
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional
11 months
The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy
11 months
The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.