{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-F8D54E43",
  "slug": "cve-2026-93485-wordpress-711-unauth-comment-xss",
  "title": "WordPress unauth comment XSS before 7.1.1",
  "aliases": [
    "CVE-2026-93485",
    "WordPress 7.1 comment XSS"
  ],
  "summary": "Unauthenticated visitors could land DOM-based XSS through WordPress core comment handling on versions before the 7.1.1 maintenance and security release (and matching backports on older trains). Upgrade to the patched train for your major version.",
  "status": "published",
  "severity": "high",
  "confidence": "high",
  "uncertainty": "Exact comment/wpautop trigger path and which backported trains are fully fixed should be confirmed against the WordPress 7.1.1 release notes for your installed major.",
  "firstObservedAt": "2026-09-18T06:04:41.504Z",
  "lastObservedAt": "2026-09-18T06:21:09.143Z",
  "publishedAt": "2026-09-20T13:02:23.231Z",
  "reviewedAt": "2026-09-20T13:02:05.747Z",
  "expiresAt": "2026-09-18T06:21:09.143Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "wordpress-711-release",
      "label": "WordPress 7.1.1 maintenance and security release",
      "url": "https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/",
      "sourceType": "vendor_advisory",
      "observedAt": "2026-09-18T00:00:00.000Z"
    },
    {
      "id": "patchstack-93485",
      "label": "Patchstack WordPress core XSS advisory",
      "url": "https://patchstack.com/database/wordpress/wordpress/wordpress/vulnerability/wordpress-wordpress-wordpress-7-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-18T06:21:09.143Z"
    },
    {
      "id": "hol-blog-93485",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-93485-wordpress-711-unauth-comment-xss",
      "sourceType": "other_primary",
      "observedAt": "2026-09-18T06:21:09.143Z"
    }
  ],
  "artifacts": [
    {
      "id": "wordpress-core",
      "artifactClass": "package",
      "ecosystem": "wordpress",
      "name": "WordPress",
      "version": "<7.1.1 (7.1 train)",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-09-18T06:04:41.504Z",
      "eventType": "disclosure",
      "summary": "CVE-2026-93485 disclosed for WordPress core unauth DOM XSS via comment handling.",
      "sourceIds": [
        "wordpress-711-release",
        "patchstack-93485"
      ]
    },
    {
      "id": "vendor-fix",
      "occurredAt": "2026-09-18T00:00:00.000Z",
      "eventType": "vendor_action",
      "summary": "WordPress 7.1.1 maintenance and security release published with the XSS fix and older-train backports.",
      "sourceIds": [
        "wordpress-711-release"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-09-18T06:21:09.143Z",
      "eventType": "other",
      "summary": "HOL Guard published the operator blog and social for CVE-2026-93485.",
      "sourceIds": [
        "hol-blog-93485"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "Not every WordPress site is on the 7.1 train — confirm your major and apply the matching security release.",
    "WAF rules are not a substitute for the core upgrade.",
    "This campaign tracks the core XSS issue, not unrelated plugin XSS in the same news cycle."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-93485-wordpress-711-unauth-comment-xss/corrections"
}
