A recently disclosed WordPress core vulnerability, dubbed Comment2Shell, allowed an anonymous commenter to embed a hidden script in a page. The attack relied on stored cross-site scripting: the malicious payload would sit quietly until a logged-in administrator opened the affected page, at which point the script would execute in the admin's browser session.
From there, the attacker could escalate the foothold into server-side remote code execution. That escalation is what makes the flaw notable — a low-privilege interaction (leaving a comment) could end with full control of the site's server, bypassing the usual separation between client-side scripting and server-side access.
WordPress has addressed the issue in a core update, and the vulnerability is tracked as CVE-2026-93485. The source report does not mention any active exploitation, but it highlights the importance of applying the patch promptly, especially for sites that allow anonymous comments. Site administrators should also review existing comments for suspicious markup if they have not yet updated.