Comment2Shell
Comment2Shell is a zero click pre auth RCE exploit for WordPress CVE-2026-93485. An anonymous comment plants stored XSS that fires when an admin views the post and drops a self deleting webshell. Full chain PoC with scanner interactive shell Nuclei template and Docker
Details
- External ID
- 1386511925
- Source
- GITHUB
- Company
- —
- Product
- Comment2Shell
- Website domain
- github.com
- Launched
- Sept. 25, 2026
- Cohort
- —
- Upvotes
- 57
- Upvotes percentile
- 0.8490263899564437
- Tags
- bug-bounty, cve-2026-93485, exploit, infosec, nuclei, nuclei-templates, poc, pre-auth, rce, security-research, web-application-security, web-exploitation, webappsec, webshell, wordpress, xss, zero-click, zeroday
- Fetched at
- Sept. 29, 2026, 5:02 p.m.
- Updated at
- Sept. 29, 2026, 5:02 p.m.
Enrichment
- Theme
- security exploits and system hacking tools
- Vertical
- Security
- Function
- Dev tools
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- proof of concept exploit for wordpress rce vulnerability
- Manually corrected
- False
Could you build this?
No Developing a full-chain zero-click unauthenticated RCE exploit against WordPress requires advanced offensive security research, vulnerability discovery, and payload crafting that AI cannot independently generate.
What it would actually take: Building this exploit suite requires identifying an unauthenticated injection flaw in WordPress comments, crafting stored XSS payloads that bypass core sanitization, and escalating privileges when an administrator renders the payload. The attack chain must automate CSRF token bypasses to upload a malicious plugin or edit templates to drop a persistent or self-deleting PHP webshell. This demands deep vulnerability research expertise, knowledge of web application exploitation, and Docker/Nuclei tooling.
Competitors
Other products that read as similar to this one — 35 launches clear the similarity bar, closest 8 shown.
Attention rank: #5 of 36 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 262 days after the earliest competitor.
- wp2shell-PoC · github · 2026-09-18 · 563 upvotes · similarity 0.53
- MarkReply - Privacy-First Comments · ph · 2026-09-18 · 1 upvotes · similarity 0.45
- cve-2026-87902-poc · github · 2026-09-22 · 31 upvotes · similarity 0.43
- CVE-2026-42536-PoC · github · 2026-09-13 · 7 upvotes · similarity 0.43
- CVE-2025-32432-exploit-by-P34NUT · github · 2026-09-16 · 6 upvotes · similarity 0.42
- cve-2026-87902-wordpress-lfi-lab · github · 2026-09-23 · 11 upvotes · similarity 0.41
- CVE-2026-87902 · github · 2026-09-22 · 32 upvotes · similarity 0.40
- CVE-2026-87902 · github · 2026-09-22 · 9 upvotes · similarity 0.40
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.