WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability
Summary
| CVE | CVE-2026-93485 |
|---|---|
| State | PUBLISHED |
| Assigner | Patchstack |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-18 06:16:41 UTC |
| Updated | 2026-09-18 06:16:41 UTC |
| Description | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35. The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed. |
Risk And Classification
Primary CVSS: v3.1 7.1 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Problem Types: CWE-79 | CWE-79 CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
| 3.1 | CNA | CVSS | 7.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
LowCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Automattic | WordPress | affected 7.1 7.1.1 custom | Not specified |
| CNA | Automattic | WordPress | affected 7.0 7.0.4 custom | Not specified |
| CNA | Automattic | WordPress | affected 6.9 6.9.7 custom | Not specified |
| CNA | Automattic | WordPress | affected 6.8 6.8.8 custom | Not specified |
| CNA | Automattic | WordPress | affected 6.7 6.7.7 custom | Not specified |
| CNA | Automattic | WordPress | affected 6.6 6.6.7 custom | Not specified |
| CNA | Automattic | WordPress | affected 6.5 6.5.10 custom | Not specified |
| CNA | Automattic | WordPress | affected 6.4 6.4.10 custom | Not specified |
| CNA | Automattic | WordPress | affected 6.3 6.3.10 custom | Not specified |
| CNA | Automattic | WordPress | affected 6.2 6.2.11 custom | Not specified |
| CNA | Automattic | WordPress | affected 6.1 6.1.12 custom | Not specified |
| CNA | Automattic | WordPress | affected 6.0 6.0.14 custom | Not specified |
| CNA | Automattic | WordPress | affected 5.9 5.9.16 custom | Not specified |
| CNA | Automattic | WordPress | affected 5.8 5.8.15 custom | Not specified |
| CNA | Automattic | WordPress | affected 5.7 5.7.17 custom | Not specified |
| CNA | Automattic | WordPress | affected 5.6 5.6.19 custom | Not specified |
| CNA | Automattic | WordPress | affected 5.5 5.5.20 custom | Not specified |
| CNA | Automattic | WordPress | affected 5.4 5.4.21 custom | Not specified |
| CNA | Automattic | WordPress | affected 5.3 5.3.23 custom | Not specified |
| CNA | Automattic | WordPress | affected 5.2 5.2.26 custom | Not specified |
| CNA | Automattic | WordPress | affected 5.1 5.1.24 custom | Not specified |
| CNA | Automattic | WordPress | affected 5.0 5.0.27 custom | Not specified |
| CNA | Automattic | WordPress | affected 4.9 4.9.31 custom | Not specified |
| CNA | Automattic | WordPress | affected 4.8 4.8.30 custom | Not specified |
| CNA | Automattic | WordPress | affected 4.7 4.7.35 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| patchstack.com/database/wordpress/wordpress/wordpress/vulnerability/wordpres... | [email protected] | patchstack.com | |
| wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release | [email protected] | wordpress.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Rafie Muhammad | Patchstack Bug Bounty Program (en)
Additional Advisory Data
Solutions
CNA: Update the WordPress to the latest available version of it's version range: 7.1.1, 7.0.5, 6.9.8, 6.8.9, 6.7.8, 6.6.8, 6.5.11, 6.4.11, 6.3.11, 6.2.12, 6.1.13, 6.0.15, 5.9.17, 5.8.16, 5.7.18, 5.6.20, 5.5.21, 5.4.22, 5.3.24, 5.2.27, 5.1.25, 5.0.28, 4.9.32, 4.8.31, 4.7.36
There are currently no legacy QID mappings associated with this CVE.