TGViewer
🛡 Cybersecurity & Privacy 🛡 - News 🛡 Cybersecurity & Privacy 🛡 - News @cibsecurity · 28.4K subscribers
Post #91019 185
🖋️ WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session 🖋️

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a loggedin administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE202693485 and called "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away. There is.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
More from @cibsecurity
  1. Oct 1, 2026📢 UK schools are getting better at dealing with cyber attacks 📢 Most now say they can re…
  2. Oct 1, 2026📢 Vulnerability disclosures are rocketing, but AI is changing the types of flaw being dis…
  3. Oct 1, 2026📢 Vulnerability disclosures are rocketing, but AI is changing the types of flaw being dis…
  4. Oct 1, 2026🌊 18 Best Threat Hunting Tools in 2026: Enterprise Platforms, Open-Source & AI-Native 🌊…
  5. Sep 28, 2026🦅 Attack Surface Management in 2026: Why Point-in-Time Scans Can’t Keep Up With Cloud Spr…
  6. Sep 28, 2026🌊 UnderDefense Launches MAXI Service Desk, Delivering Direct Native Support for Enterpris…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →