7.1
CVE-2026-93485 (Comment2Shell)
- EPSS 0.16%
- Veröffentlicht 18.09.2026 06:00:05
- Zuletzt bearbeitet 19.09.2026 15:17:08
- Erkennungen
WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability
WordPress Core <= 7.1 - Unauthenticated Stored Cross-Site Scripting via wpautop() Blockquote Handling
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS.
This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35.
The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.Mögliche Gegenmaßnahme
WordPress: Update to one of the following versions, or a newer patched version: 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version
7.1
Version <
7.1.1
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
7.0.4
Version
7.0
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
6.9.7
Version
6.9
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
6.8.8
Version
6.8
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
6.7.7
Version
6.7
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
6.6.7
Version
6.6
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
6.5.10
Version
6.5
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
6.4.10
Version
6.4
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
6.3.10
Version
6.3
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
6.2.11
Version
6.2
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
6.1.12
Version
6.1
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
6.0.14
Version
6.0
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
5.9.16
Version
5.9
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
5.8.15
Version
5.8
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
5.7.17
Version
5.7
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
5.6.19
Version
5.6
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
5.5.20
Version
5.5
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
5.4.21
Version
5.4
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
5.3.23
Version
5.3
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
5.2.26
Version
5.2
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
5.1.24
Version
5.1
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
5.0.27
Version
5.0
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
4.9.31
Version
4.9
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
4.8.30
Version
4.8
Status
affected
HerstellerAutomattic
≫
Produkt
WordPress
Default Statusunaffected
Version <=
4.7.35
Version
4.7
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Core
≫
Produkt
WordPress
Version
*-6.6.7
Version
6.7-6.7.7
Version
6.8-6.8.8
Version
6.9-6.9.7
Version
7.0-7.0.4
Version
7.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.057 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| audit@patchstack.com | 7.1 | 2.8 | 3.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://patchstack.com/database/wordpress/wordpress/wordpress/vulnerability/wordpress-wordpress-wordpress-7-1-cross-site-scripting-xss-vulnerability?_s_id=cve
https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/
https://www.wordfence.com/threat-intel/vulnerabilities/id/1984abee-a74c-48d7-874f-c4421243e5e5