Web Hack List

Preliminary research

Comment2XSS: chained comment-formatting transformations in WordPress

Comment2XSS: Zero-Click Pre-Auth XSS to Potential RCE in WordPress Core

AI-collected research leads through 24 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

A permitted comment attribute newline becomes an HTML-comment placeholder. A quote-unaware wpautop rewrite inserts markup inside it; subsequent texturization changes quoting and turns safe text into an event handler. The report covers rendering prerequisites, moderation routes and conditional administrator-session plugin-upload escalation.

Record

Document
Comment2XSS: Zero-Click Pre-Auth XSS to Potential RCE in WordPress Core
Researcher
Rafie Muhammad
Published by
IDNSEC
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Rafie Muhammad, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .