CVE-2026-93485: WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS.
This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35.
The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 7.1.1 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 7.0.5 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 6.9.8 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 6.8.9 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 6.7.8 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 6.6.8 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 6.5.11 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 6.4.11 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 6.3.11 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 6.2.12 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 6.1.13 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 6.0.15 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 5.9.17 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 5.8.16 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 5.7.18 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 5.6.20 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 5.5.21 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 5.4.22 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 5.3.24 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 5.2.27 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 5.1.25 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 5.0.28 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 4.9.32 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 4.8.31 - Upgrade
Upgrade
Automattic WordPress coreto a version that resolves this vulnerability.Fixed in 4.7.36
Event History
Frequently Asked Questions
Which installations are exposed by default?
A default WordPress installation is affected if it runs one of the listed vulnerable releases. The issue can be reproduced with the default configuration because comment moderation is disabled by default.
Does an attacker need an account or elevated permissions?
No. The vulnerability is described as unauthenticated stored XSS, so an attacker does not need a WordPress account or privileges. Exploitation requires user interaction, as reflected by the UI:R vector.
Does requiring previously approved commenters prevent exploitation?
No. The requirement for commenters to have a previously approved comment can be bypassed, so it should not be relied on as a mitigation.
Which releases contain fixes?
The affected ranges indicate fixes in WordPress 7.1.1, 7.0.5, 6.9.8, 6.8.9, 6.7.8, 6.6.8, 6.5.11, 6.4.11, 6.3.11, 6.2.12, 6.1.13, 6.0.15, 5.9.17, 5.8.16, 5.7.18, 5.6.20, 5.5.21, 5.4.22, 5.3.24, 5.2.27, 5.1.25, 5.0.28, 4.9.32, 4.8.31, and 4.7.36.