Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. (CVE-2026-93485)
A cross-site scripting (XSS) vulnerability exists in the Automattic WordPress core due to improper neutralization of input during web page generation, allowing DOM-based XSS attacks. This vulnerability affects multiple WordPress versions from 4.7 through 7.1 before 7.1.1. The issue can be reproduced on a default WordPress installation with comment moderation disabled, and the requirement for commenters to have a previously approved comment can be bypassed.
AI Analysis
Technical Summary
CVE-2026-93485 is a DOM-based cross-site scripting vulnerability in the Automattic WordPress core caused by improper input neutralization during web page generation. It affects a wide range of WordPress versions starting from 4.7 up to versions before 7.1.1. The vulnerability allows unauthenticated attackers to inject malicious scripts, leveraging the default configuration where comment moderation is disabled and the approval requirement for commenters can be bypassed. This issue can be reproduced on a default WordPress installation without additional configuration.
Potential Impact
Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary scripts in the context of the victim's browser, potentially leading to information disclosure, session hijacking, or other client-side impacts. The vulnerability affects confidentiality, integrity, and availability as indicated by the CVSS vector (C:L/I:L/A:L).
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, consider enabling comment moderation and restricting comment approvals to mitigate the risk of exploitation. Monitor official WordPress security channels for updates and apply patches promptly once released.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. (CVE-2026-93485)
Description
A cross-site scripting (XSS) vulnerability exists in the Automattic WordPress core due to improper neutralization of input during web page generation, allowing DOM-based XSS attacks. This vulnerability affects multiple WordPress versions from 4.7 through 7.1 before 7.1.1. The issue can be reproduced on a default WordPress installation with comment moderation disabled, and the requirement for commenters to have a previously approved comment can be bypassed.
CVSS v3.1
Score 7.1high
Affected software
pkg:deb/ubuntu/wordpress?arch=source&distro=xenialpkg:deb/ubuntu/wordpress?arch=source&distro=bionicpkg:deb/ubuntu/wordpress?arch=source&distro=focalpkg:deb/ubuntu/wordpress?arch=source&distro=jammypkg:deb/ubuntu/wordpress?arch=source&distro=noblepkg:deb/ubuntu/wordpress?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93485 is a DOM-based cross-site scripting vulnerability in the Automattic WordPress core caused by improper input neutralization during web page generation. It affects a wide range of WordPress versions starting from 4.7 up to versions before 7.1.1. The vulnerability allows unauthenticated attackers to inject malicious scripts, leveraging the default configuration where comment moderation is disabled and the approval requirement for commenters can be bypassed. This issue can be reproduced on a default WordPress installation without additional configuration.
Potential Impact
Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary scripts in the context of the victim's browser, potentially leading to information disclosure, session hijacking, or other client-side impacts. The vulnerability affects confidentiality, integrity, and availability as indicated by the CVSS vector (C:L/I:L/A:L).
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, consider enabling comment moderation and restricting comment approvals to mitigate the risk of exploitation. Monitor official WordPress security channels for updates and apply patches promptly once released.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-93485
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab4be2ef7a7c54106eeec2d
Added to database: 09/24/2026, 06:07:42 UTC
Last enriched: 09/24/2026, 06:31:24 UTC
Last updated: 09/25/2026, 04:47:34 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.