Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)

Comment2Shell (TL-2026-2717), also tracked as Comment2Shell, is a high-severity software vulnerability scored CVSS 7.1, first published 2026-09-27. It has no confirmed attribution, affects WordPress / Automattic WordPress Core, references 1 CVE (CVE-2026-93485), maps to 9 MITRE ATT&CK techniques (T1036, T1059, T1059.007), and is covered by 9 detection rules and 11 indicators of compromise.

Key facts for TL-2026-2717

Threat ID
TL-2026-2717
Also known as
Comment2Shell, Comment2XSS
Severity
HIGH
CVSS
7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-27
Last reviewed
2026-09-27
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
11

Malware and tooling in Comment2Shell

Malware and tooling: Comment2Shell

The public "Comment2Shell" PoC chains an unauthenticated stored XSS in WordPress core's wpautop() comment-formatting logic into remote code execution: a newline hidden inside a blockquote cite attribute survives KSES sanitization, and a regex in wpautop() that stops at the first '>' injects a stray tag that lets onfocus/autofocus fire JavaScript the instant an administrator views the comment. That zero-click script then steals the plugin-install nonce, builds a plugin ZIP in-browser, and uploads a self-deleting PHP webshell. Affects WordPress 4.7 through 7.1.0; fixed in 7.1.1 with backports down to 4.7.36.

How Comment2Shell works

CVE-2026-93485 ("Comment2Shell") is a five-step exploit chain in WordPress core that turns an anonymous blog comment into full remote code execution on the underlying server.

The chain begins at the input layer: WordPress's KSES HTML sanitizer allows the `cite` attribute on an allow-listed `<blockquote>` element, but its encoding map does not account for a raw newline character, so a comment body containing `<blockquote cite="a b"><code>x" onfocus=... autofocus</code></blockquote>` is stored verbatim. The vulnerability is purely a display-time bug, not an input-validation gap: the same content is safe as stored text and only becomes dangerous when WordPress re-renders it.

At render time, `wpautop()` (wp-includes/formatting.php, line 563 in vulnerable releases) converts the embedded newline into an HTML-comment placeholder. The function's tag-matching regex, `|<p><blockquote([^>]*)>|i`, uses a `[^>]*` character class that cannot traverse a quoted attribute boundary, so it stops at the first bare `>` -- the closing bracket of the injected placeholder comment -- and mis-inserts a `<p>` tag in the middle of the `cite` attribute. `wptexturize()` then treats that misplaced `<p>` as a real tag boundary and re-encodes straight quotes as curly-quote entities everywhere except inside the attacker's `<code>` block, which finalizes a syntactically valid `onfocus`/`autofocus` attribute pair in the resulting DOM.

Because `autofocus` fires `onfocus` without any user gesture, the payload executes the instant a logged-in administrator's browser renders the comment moderation queue or the post itself -- true zero-click execution inside the admin's authenticated session. From there the injected JavaScript reads the `_wpnonce` value out of the `/wp-admin/plugin-install.php?tab=upload` form, constructs a ZIP archive entirely in browser memory containing a minimal WordPress plugin whose only file is a PHP web shell, and POSTs it to `/wp-admin/update.php?action=upload-plugin`. WordPress installs and the plugin directory becomes web-accessible immediately -- no activation step is required for the dropped PHP to execute, since the attacker can request it directly.

The resulting shell supports arbitrary command execution via a `c` query parameter and, by default, self-deletes after use via a `d=1` parameter, unlinking its own PHP file and removing the plugin directory to erase the most obvious forensic artifact. An `--no-cleanup` flag in the public tooling can retain the shell for persistent access instead.

Exploitation additionally depends on getting the payload in front of an administrator, which the researcher demonstrated can happen even under default moderation settings: reusing the identity of WordPress's default "A WordPress Commenter" seed record triggers auto-approval in `check_comment()`, disabling "comment author must have a previously approved comment" removes moderation entirely, and even a still-pending comment can be rendered to a victim who follows an attacker-supplied `?unapproved=<id>&moderation-hash=<hash>` preview link.

WordPress 7.1.1 (released 2026-09-17) fixed the root cause by replacing the vulnerable regex with a quote-aware alternation, `!<p><blockquote((?:[^>"']|"[^"]*"|'[^']*')*)>!i`, that correctly tracks quoted attribute boundaries and no longer breaks on an embedded comment placeholder. The fix, and ten unrelated security fixes, shipped simultaneously and was backported to every WordPress branch still receiving security support, down to 4.7.36. A dependency-free Python PoC (`comment2shell.py`) with scanning, exploitation, interactive-shell, and IOC-detection modes, plus a Nuclei template, was published publicly on GitHub six days after the patch, materially lowering the skill floor for exploitation. No confirmed in-the-wild exploitation or CISA KEV listing existed at the time of this research.

MITRE ATT&CK techniques used in TL-2026-2717

Defense Evasion

T1036 Masquerading; T1070.004 File Deletion

Execution

T1059 Command and Scripting Interpreter; T1059.007 JavaScript

Collection

T1185 Browser Session Hijacking

Initial Access

T1190 Exploit Public-Facing Application

Persistence

T1505.003 Web Shell

Resource Development

T1588.005 Exploits

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in Comment2Shell

  • WordPress / Automattic — WordPress Core
    Vulnerable versions: 4.7-4.7.35; 4.8-4.8.30; 4.9-4.9.31; 5.0-5.0.27; 5.1-5.1.24; 5.2-5.2.26; 5.3-5.3.23; 5.4-5.4.21; 5.5-5.5.20; 5.6-5.6.19
    Fixed in: 7.1.1; 7.0.5; 6.9.8; 6.8.9; 4.7.36 and the equivalent point release on every intermediate branch

Remediation for Comment2Shell

Patches

  • WordPress 7.1.1
  • WordPress 7.0.5
  • WordPress 6.9.8
  • WordPress 6.8.9
  • WordPress 4.7.36 (and the equivalent point release on every intermediate branch)

Immediate actions

  • Update WordPress core to 7.1.1, or the matching backported fix for older branches (7.0.5, 6.9.8, 6.8.9, or the equivalent point release down to 4.7.36)
  • Disable comments site-wide or on individual posts until the update is applied
  • Audit wp-content/plugins/ for unrecognized single-file plugin directories with randomized names and PHP files newer than wp-config.php
  • Query the wp_comments table for entries containing 'blockquote', 'cite', and 'onfocus'/'autofocus' and quarantine or delete any matches
  • If a webshell or unexpected plugin is found, treat the admin session as compromised: rotate WordPress secret keys/salts, force-expire all active sessions, and rotate hosting/database credentials

Workarounds

  • Disable anonymous/unauthenticated commenting and require registered, logged-in commenters
  • Close comments on all published posts and pages until patched
  • Enable strict comment moderation so no new commenter's content is ever auto-published or auto-previewed to an administrator

Longer-term hardening

  • Enable 'comment author must have a previously approved comment' and disable auto-approval for reused default/seed commenter identities
  • Deploy a WAF rule blocking raw newline characters and onfocus/autofocus/onload attribute injection in submitted comment fields
  • Alert on plugin uploads via /wp-admin/update.php?action=upload-plugin that occur immediately after an administrator views new comment content
  • Restrict administrator review of unmoderated/anonymous comment content to a hardened, script-disabled review interface

CVEs associated with Comment2Shell

CVE-2026-93485

Weaknesses (CWE) in Comment2Shell

CWE-79

Timeline of Comment2Shell

  • Rafie Muhammad (Awesome Motive, Inc.) reports the wpautop() stored XSS to the WordPress Security Team via the WordPress HackerOne coordinated-disclosure program.
  • A CVE identifier request for the vulnerability is submitted to Patchstack.
  • WordPress releases 7.1.1, one of 11 security fixes in the release, correcting the wpautop() regex with a quote-aware pattern; backports ship for 7.0 (7.0.5), 6.9 (6.9.8), and every supported branch down to 4.7.36.
  • CVE-2026-93485 is formally assigned and published (CWE-79), as reflected in Tenable and OffSeq threat-intelligence listings.
  • Conicplex publishes a technical writeup detailing the pre- and post-patch wpautop() regex and the vulnerability's exploitation conditions.
  • idnsec publishes "Comment2XSS: Zero-Click Pre-Auth XSS to Potential RCE in WordPress Core," a full technical breakdown of the KSES bypass, regex flaw, and comment-moderation bypass techniques.
  • MagicWP publishes patch-analysis coverage confirming the Patchstack-assigned CVSS 3.1 vector (7.1, HIGH) and mitigation guidance.
  • Syed Wajeeh-ul-Hassan Rizvi publishes the "Comment2Shell" end-to-end proof-of-concept on GitHub (DeathShotXD/Comment2Shell), including a dependency-free Python exploit/scanner, interactive shell, Nuclei template, and Docker lab environment.
  • Cyber Security News publishes coverage of the Comment2Shell PoC, surfacing the threat for tracking as TL-2026-2717.

Sources cited for Comment2Shell

More in vulnerability

Detection coverage for TL-2026-2717

As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2717 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats