security1 publisher
WordPress patched a comment flaw that uses an admin's session to plant a web shell
CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.
Publishers:thehackernews.com
Reality
- Evidence72
- Adoption25
- Hype gap+8
- Incentives55
- Confidence62