Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS.


This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35.




The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.
Published: 2026-09-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted client‑side code execution via XSS
Action: Update Immediately
AI Analysis

Impact

WordPress core improperly neutralizes user input, resulting in a DOM‑based cross‑site scripting vulnerability (CWE-79). An attacker can inject malicious script into a web page rendered by WordPress. When a victim visits that page, the script runs in the victim’s browser, enabling attackers to capture cookies, hijack sessions, deface content, or launch phishing attacks. The issue is pronounced for users within the site or anyone who views the affected content.

Affected Systems

The flaw affects the Automattic WordPress core across a wide range of releases, from 4.7 through the 7.1 line. Versions 7.1 and earlier, 7.0 through 7.0.4, 6.9 through 6.9.7, 6.8 through 6.8.8, 6.7 through 6.7.7, 6.6 through 6.6.7, 6.5 through 6.5.10, 6.4 through 6.4.10, 6.3 through 6.3.10, 6.2 through 6.2.11, 6.1 through 6.1.12, 6.0 through 6.0.14, 5.9 through 5.9.16, 5.8 through 5.8.15, 5.7 through 5.7.17, 5.6 through 5.6.19, 5.5 through 5.5.20, 5.4 through 5.4.21, 5.3 through 5.3.23, 5.2 through 5.2.26, 5.1 through 5.1.24, 5.0 through 5.0.27, 4.9 through 4.9.31, 4.8 through 4.8.30 and 4.7 through 4.7.35 are all impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity flaw. EPSS is reported as < 1 %, meaning the overall likelihood of exploitation remains low at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can execute it without authentication via web requests (e.g., by posting a crafted comment that bypasses the default moderation requirement). Successful exploitation results in client‑side code execution that can be leveraged for a range of attacks, including session hijacking and phishing.

Generated by OpenCVE AI on September 19, 2026 at 21:31 UTC.

Remediation

Vendor Solution

Update the WordPress to the latest available version of it's version range: 7.1.1, 7.0.5, 6.9.8, 6.8.9, 6.7.8, 6.6.8, 6.5.11, 6.4.11, 6.3.11, 6.2.12, 6.1.13, 6.0.15, 5.9.17, 5.8.16, 5.7.18, 5.6.20, 5.5.21, 5.4.22, 5.3.24, 5.2.27, 5.1.25, 5.0.28, 4.9.32, 4.8.31, 4.7.36


OpenCVE Recommended Actions

  • Upgrade WordPress to the latest release (7.1.1 or later) to patch the XSS flaw
  • Verify that comment moderation settings are enabled if the site relies on moderation to process user input
  • Employ an additional security plugin or service that validates and escapes user‑supplied data to guard against similar injection attacks

Generated by OpenCVE AI on September 19, 2026 at 21:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6525-1 wordpress security update
History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Automattic
Automattic wordpress
Vendors & Products Automattic
Automattic wordpress

Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35. The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.
Title WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Automattic Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-19T14:21:52.478Z

Reserved: 2026-09-18T05:11:39.339Z

Link: CVE-2026-93485

cve-icon Vulnrichment

Updated: 2026-09-19T14:14:45.185Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:41.970

Modified: 2026-09-19T15:17:08.323

Link: CVE-2026-93485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')