CVE-2026-93485
Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS.
This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35.
The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <7.1.1, 7.0-7.0.4, 6.9-6.9.7, 6.8-6.8.8, 6.7-6.7.7, 6.6-6.6.7, 6.5-6.5.10, 6.4-6.4.10, 6.3-6.3.10, 6.2-6.2.11, 6.1-6.1.12, 6.0-6.0.14, 5.9-5.9.16, 5.8-5.8.15, 5.7-5.7.17, 5.6-5.6.19, 5.5-5.5.20, 5.4-5.4.21, 5.3-5.3.23, 5.2-5.2.26, 5.1-5.1.24, 5.0-5.0.27, 4.9-4.9.31, 4.8-4.8.30, 4.7-4.7.35
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.