highCVE-2026-93485

WordPress Core Unauthenticated Stored XSS via Comments - CVE-2026-93485

WordPress core versions 4.7 through 7.1.0 (fixed in 7.1.1) are vulnerable to unauthenticated stored cross-site scripting via the comment submission endpoint. Comment moderation is disabled by default and the requirement for a previously approved comment can be bypassed, permitting unauthenticated attackers to inject persistent JavaScript (DOM-Based XSS). This template fingerprints the WordPress version via the RSS feed generator tag to identify affected installations without triggering the vulnerability.

Enter a domain you own and we will test it right now — and, while we are there, report anything else it exposes publicly. No account, no agent to install.

No signup. Takes about a minute. We request pages your server already serves publicly — nothing is written, exploited or brute-forced.

Tags

cvecve2026wordpressxssdom-xsscms
Is your site vulnerable to CVE-2026-93485? Free check — WordPress Core Unauthenticated Stored XSS via Comments - CVE-2026-93485