security6 publishers
WordPress patched a comment flaw that uses an admin's session to plant a web shell
CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.
Publishers:bleepingcomputer.comhelpnetsecurity.comorca.securitysecurityaffairs.comsecurityweek.comthehackernews.com
Perspective Coverage
6 publishers- Builder
- Builder 23%
- Operator
- Operator 68%
- Investor
- Investor 9%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence62