Comment2Shell
Comment2Shell is a zero click pre auth RCE exploit for WordPress CVE-2026-93485. An anonymous comment plants stored XSS that fires when an admin views the post and drops a self deleting webshell. Full chain PoC with scanner interactive shell Nuclei template and Docker
- bug-bounty
- exploit
- infosec
- nuclei
- nuclei-templates
- poc
- pre-auth
- rce
- security-research
- web-application-security
- web-exploitation
- webappsec
- webshell
- wordpress
- xss
- Stars
- 62
- Forks
- 14
- + today
- +1
- Created
- 11d
Ranking data as of October 5, 2026 (UTC).
Star History
Today, hour by hour
01
Overview
Comment2Shell is a zero click pre auth RCE exploit for WordPress CVE-2026-93485. An anonymous comment plants stored XSS that fires when an admin views the post and drops a self deleting webshell. Full chain PoC with scanner interactive shell Nuclei template and Docker It ranks #1421 on GitTiger, gaining +1 star on October 5, 2026 (UTC).
The project is written in Python and has 14 forks. It was created 11d ago.
Installation
git clone https://github.com/DeathShotXD/Comment2Shell.git
cd Comment2Shell
# see README for setup