thehackernews.com 22 Sept 2026, 06:03 UTC

WordPress Comment2Shell Bug Lets Anonymous Users Hijack Admin Sessions

WordPress Comment2Shell Bug Lets Anonymous Users Hijack Admin Sessions
CyberSIXT Evidence Panel Source marked as original reporting

THE article discusses a vulnerability found in WordPress' Comment2Shell system that allows anonymous comments to escalate to remote code execution (RCE) through an admin session. This flaw poses significant security risks for WordPress sites, potentially compromising sensitive data and administrative controls. It emphasizes the need for users to update their systems to the latest versions to mitigate the threat.

View full article

Article by CyberSIXT