DIRAS TAKE
Treat this as high priority: public exploit code exists for CVE-2026-93485, so sites reachable by untrusted users should be updated or mitigated immediately.
What is CVE-2026-93485?
Attackers can run JavaScript in site visitors' browsers on vulnerable WordPress installs, enabling session theft, redirection, or other client-side impacts. CVE-2026-93485 is a DOM-based XSS in WordPress core that affects multiple 6.x and 7.x releases, including 7.1 before 7.1.1 and several 7.0 and 6.x ranges listed by the vendor. Exploitation requires network access to the site and user interaction (a victim visiting a crafted page or clicking a link). The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Which versions of Automattic WordPress are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | 7.1 – before 7.1.1 | 7.1.1 |
| 7.x | 7.0 – 7.0.4 | |
| 6.x | 6.9 – 6.9.7 | |
| 6.x | 6.8 – 6.8.8 | |
| 6.x | 6.7 – 6.7.7 | |
| 6.x | 6.6 – 6.6.7 | |
| 6.x | 6.5 – 6.5.10 | |
| 6.x | 6.4 – 6.4.10 | |
| 6.x | 6.3 – 6.3.10 | |
| 6.x | 6.2 – 6.2.11 |
Is CVE-2026-93485 being exploited?
Public exploit code is available.
How to fix CVE-2026-93485
- If running WordPress 7.1, upgrade to 7.1.1 which contains the fix.
- Apply any vendor-supplied updates or guidance for your installed branch as soon as they are published.
- Restrict exposure of administrative and comment-handling endpoints to trusted networks where practical.
- Monitor web logs and JavaScript-related errors for suspicious inputs or unexpected redirects.
Frequently asked questions
Is CVE-2026-93485 being actively exploited?
Public exploit code is available, but there are no public reports of active exploitation as of 2026-09-30.
Which WordPress versions are affected by CVE-2026-93485?
Multiple 6.x branches and 7.x releases are affected; specifically 7.1 before 7.1.1 and several 7.0 and 6.x ranges listed by the vendor are included.
Is there a patch for CVE-2026-93485?
A patch is available for the 7.1 branch (fixed in 7.1.1); the vendor has listed affected ranges and notes updates where provided.
Does CVE-2026-93485 require authentication?
No authentication is required to exploit this DOM-based XSS; an attacker needs a victim to load a crafted page or click a crafted link.
References
- nvd.nist.gov/vuln/detail/CVE-2026-93485
- cve.org/CVERecord?id=CVE-2026-93485
- patchstack.com/database/wordpress/wordpress/wordpress/vulnerability/wordpress-wordpress-wordpress-7-1-cross-site-scripting-xss-vulnerability?_s_id=cve
- wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release
- All Automattic CVEs on CVE Radar
- CVEs published in September 2026