Skip to content

security_identifier

CVE-2026-93485

CVE record for a WordPress core comment-handling flaw, nicknamed Comment2Shell, in which markup that survives save-time filtering is rewritten at render time into an executing event handler.

Known aliases

  • Comment2Shell

Relationships

No evidence-backed relationships are recorded.

Current clusters