CVE-2026-93485

HIGHCVSS 7.1/10

Last modified

CVE-2026-93485 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35. The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed..

Description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35. The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
AutomatticWordPress>= 7.1, < 7.1.1
AutomatticWordPress>= 7.0, <= 7.0.4
AutomatticWordPress>= 6.9, <= 6.9.7
AutomatticWordPress>= 6.8, <= 6.8.8
AutomatticWordPress>= 6.7, <= 6.7.7
AutomatticWordPress>= 6.6, <= 6.6.7
AutomatticWordPress>= 6.5, <= 6.5.10
AutomatticWordPress>= 6.4, <= 6.4.10
AutomatticWordPress>= 6.3, <= 6.3.10
AutomatticWordPress>= 6.2, <= 6.2.11
AutomatticWordPress>= 6.1, <= 6.1.12
AutomatticWordPress>= 6.0, <= 6.0.14
AutomatticWordPress>= 5.9, <= 5.9.16
AutomatticWordPress>= 5.8, <= 5.8.15
AutomatticWordPress>= 5.7, <= 5.7.17
AutomatticWordPress>= 5.6, <= 5.6.19
AutomatticWordPress>= 5.5, <= 5.5.20
AutomatticWordPress>= 5.4, <= 5.4.21
AutomatticWordPress>= 5.3, <= 5.3.23
AutomatticWordPress>= 5.2, <= 5.2.26
AutomatticWordPress>= 5.1, <= 5.1.24
AutomatticWordPress>= 5.0, <= 5.0.27
AutomatticWordPress>= 4.9, <= 4.9.31
AutomatticWordPress>= 4.8, <= 4.8.30
AutomatticWordPress>= 4.7, <= 4.7.35

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2026-93485?
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35. The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.
How severe is CVE-2026-93485?
CVE-2026-93485 has a CVSS score of 7.1/10 (HIGH severity).
How do I fix CVE-2026-93485?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-93485?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST