CVE-2026-93485 PUBLISHED

WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability

Assigner: Patchstack
Reserved: 18.09.2026 Published: 18.09.2026 Updated: 18.09.2026

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS.

This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35.

The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CVSS Score: 7.1

Product Status

Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 7.1 to 7.1.1 (excl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 7.0 to 7.0.4 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 6.9 to 6.9.7 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 6.8 to 6.8.8 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 6.7 to 6.7.7 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 6.6 to 6.6.7 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 6.5 to 6.5.10 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 6.4 to 6.4.10 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 6.3 to 6.3.10 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 6.2 to 6.2.11 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 6.1 to 6.1.12 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 6.0 to 6.0.14 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 5.9 to 5.9.16 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 5.8 to 5.8.15 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 5.7 to 5.7.17 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 5.6 to 5.6.19 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 5.5 to 5.5.20 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 5.4 to 5.4.21 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 5.3 to 5.3.23 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 5.2 to 5.2.26 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 5.1 to 5.1.24 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 5.0 to 5.0.27 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 4.9 to 4.9.31 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 4.8 to 4.8.30 (incl.)
Vendor Automattic
Product WordPress
Versions Default: unaffected
  • affected from 4.7 to 4.7.35 (incl.)

Solutions

Update the WordPress to the latest available version of it's version range: 7.1.1, 7.0.5, 6.9.8, 6.8.9, 6.7.8, 6.6.8, 6.5.11, 6.4.11, 6.3.11, 6.2.12, 6.1.13, 6.0.15, 5.9.17, 5.8.16, 5.7.18, 5.6.20, 5.5.21, 5.4.22, 5.3.24, 5.2.27, 5.1.25, 5.0.28, 4.9.32, 4.8.31, 4.7.36

Credits

  • Rafie Muhammad | Patchstack Bug Bounty Program finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE

Impacts

  • CAPEC-588 DOM-Based XSS