Junglewise Threat Intelligence

CVE-2026-93485: Automattic WordPress core stored XSS in wpautop()

CVE-2026-93485 · Severity: high · CVSS 7.1 · Published 2026-09-18

Vendors: Automattic.

Executive brief

WordPress is the most widely-used content management system for websites. A stored cross-site scripting (XSS) vulnerability in the wpautop() function allows unauthenticated attackers to inject malicious scripts into comments that are displayed to site visitors. If exploited successfully, attackers can steal visitor data, hijack user accounts, or compromise website integrity without requiring administrative privileges.

Technical details

The vulnerability is a DOM-based stored XSS in WordPress core's wpautop() function affecting comment processing. An unauthenticated attacker can inject malicious JavaScript payloads via comments; comment moderation is disabled by default, and the requirement for an attacker to have a previously approved comment can be bypassed. Once injected, the malicious script executes in the browsers of site visitors viewing the affected comment. The vulnerability was discovered and reported by Rafie Muhammad and fixed in WordPress 7.1.1 (released September 17, 2026). Security patches have been backported to all supported versions from 4.7 onwards.

Affected products

  • Automattic WordPress 4.7 through 7.1 before 7.1.1 (all minor versions between 4.7 and 7.0.4, 6.0 through 7.1)

Timeline

  • 2026-09-15: disclosed: Vulnerability reported by Rafie Muhammad
  • 2026-09-18: advisory: Published by Patchstack; early warning sent to customers
  • 2026-09-17: patched: WordPress 7.1.1 released with security fixes; backports in progress for 4.7–7.0.x

References