highCVE-2026-93485
WordPress Core Unauthenticated Stored XSS via Comments - CVE-2026-93485
WordPress core versions 4.7 through 7.1.0 (fixed in 7.1.1) are vulnerable to unauthenticated stored cross-site scripting via the comment submission endpoint. Comment moderation is disabled by default and the requirement for a previously approved comment can be bypassed, permitting unauthenticated attackers to inject persistent JavaScript (DOM-Based XSS). This template fingerprints the WordPress version via the RSS feed generator tag to identify affected installations without triggering the vulnerability.
Enter a domain you own and we will test it right now — and, while we are there, report anything else it exposes publicly. No account, no agent to install.
Tags
cvecve2026wordpressxssdom-xsscms