Comment2Shell is a zero click pre auth RCE exploit for WordPress CVE-2026-93485. An anonymous comment plants stored XSS that fires when an admin views the post and drops a self deleting webshell. Full chain PoC with scanner interactive shell Nuclei template and Docker
wordpress exploit xss poc rce bug-bounty infosec nuclei webshell webappsec web-exploitation web-application-security security-research zeroday pre-auth zero-click nuclei-templates cve-2026-93485
-
Updated
Oct 6, 2026 - Python