• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-93485: dom-based cross-site scripting in Automattic WordPress

Attackers can run JavaScript in site visitors' browsers on vulnerable WordPress installs, enabling session theft, redirection, or other client-side impacts. CVE-2026-93485 is a DOM-based XSS in WordPress core that affects multiple 6.x and 7.x releases, including 7.1 before 7.1.1 and several 7.0 and 6.x ranges listed by the vendor. Exploitation requires network access to the site and user interaction (a victim visiting a crafted page or clicking a link).

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.1HIGH
EPSS
0.00375
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as high priority: public exploit code exists for CVE-2026-93485, so sites reachable by untrusted users should be updated or mitigated immediately.

What is CVE-2026-93485?

Attackers can run JavaScript in site visitors' browsers on vulnerable WordPress installs, enabling session theft, redirection, or other client-side impacts. CVE-2026-93485 is a DOM-based XSS in WordPress core that affects multiple 6.x and 7.x releases, including 7.1 before 7.1.1 and several 7.0 and 6.x ranges listed by the vendor. Exploitation requires network access to the site and user interaction (a victim visiting a crafted page or clicking a link). The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Which versions of Automattic WordPress are affected?

BRANCHAFFECTEDFIXED
7.x7.1 – before 7.1.17.1.1
7.x7.0 – 7.0.4
6.x6.9 – 6.9.7
6.x6.8 – 6.8.8
6.x6.7 – 6.7.7
6.x6.6 – 6.6.7
6.x6.5 – 6.5.10
6.x6.4 – 6.4.10
6.x6.3 – 6.3.10
6.x6.2 – 6.2.11

Is CVE-2026-93485 being exploited?

Public exploit code is available.

How to fix CVE-2026-93485

  1. If running WordPress 7.1, upgrade to 7.1.1 which contains the fix.
  2. Apply any vendor-supplied updates or guidance for your installed branch as soon as they are published.
  3. Restrict exposure of administrative and comment-handling endpoints to trusted networks where practical.
  4. Monitor web logs and JavaScript-related errors for suspicious inputs or unexpected redirects.

Frequently asked questions

Is CVE-2026-93485 being actively exploited?

Public exploit code is available, but there are no public reports of active exploitation as of 2026-09-30.

Which WordPress versions are affected by CVE-2026-93485?

Multiple 6.x branches and 7.x releases are affected; specifically 7.1 before 7.1.1 and several 7.0 and 6.x ranges listed by the vendor are included.

Is there a patch for CVE-2026-93485?

A patch is available for the 7.1 branch (fixed in 7.1.1); the vendor has listed affected ranges and notes updates where provided.

Does CVE-2026-93485 require authentication?

No authentication is required to exploit this DOM-based XSS; an attacker needs a victim to load a crafted page or click a crafted link.

References