{"type":"bundle","id":"bundle--d3878e60-34f4-58c9-9bb9-c41fbec5a9fc","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--d7c0e421-69ed-5b55-bda1-d5f6a75d5bb5","created":"2026-09-20T13:02:23.231Z","modified":"2026-09-20T13:02:05.747Z","name":"WordPress unauth comment XSS before 7.1.1","description":"Unauthenticated visitors could land DOM-based XSS through WordPress core comment handling on versions before the 7.1.1 maintenance and security release (and matching backports on older trains). Upgrade to the patched train for your major version.","aliases":["CVE-2026-93485","WordPress 7.1 comment XSS"],"first_seen":"2026-09-18T06:04:41.504Z","last_seen":"2026-09-18T06:21:09.143Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"WordPress 7.1.1 maintenance and security release","url":"https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/"},{"source_name":"Patchstack WordPress core XSS advisory","url":"https://patchstack.com/database/wordpress/wordpress/wordpress/vulnerability/wordpress-wordpress-wordpress-7-1-cross-site-scripting-xss-vulnerability?_s_id=cve"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-93485-wordpress-711-unauth-comment-xss"}]}]}