워드프레스의 신규 취약점이 익명 댓글을 통해 RCE를 유발할 수 있음.
워드프레스의 최신 취약점 'Comment2Shell'이 발견되어 익명 사용자가 코드를 실행할 수 있는 가능성이 생겼습니다. 이 취약점은 로그인한 관리자가 해당 페이지를 열 경우 악성 스크립트가 실행될 수 있게 합니다. 워드프레스는 CVE-2026-93485로 추적되는 이 문제를 7.1.1 버전에서 9월 17일 수정했으며, 사이트 운영자들에게 즉시 업데이트할 것을 권장하고 있습니다.
A new WordPress vulnerability allows anonymous comments to trigger RCE via admin session.
A new vulnerability in WordPress, dubbed 'Comment2Shell', allows anonymous visitors to leave comments that can run code on the server when viewed by a logged-in administrator. This flaw is tracked as CVE-2026-93485 and was fixed in version 7.1.1 on September 17. Site owners are urged to update their installations immediately to mitigate the risk.