TechWave AI Pulse Signal over noise
BAD SECURITY GLOBAL

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, t

The Hacker News 2 newsrooms Tue, 22 Sep 2026 06:03
Read the original at The Hacker News ↗

Also reported by 1 other newsroom