Comment2Shell is an offensive proof-of-concept. It is meant to be run only against systems you own or have explicit written permission to test. Reports about the tool's behaviour on unauthorized targets are out of scope.
Security fixes land on main. There are no long-lived release branches.
If you find a bug in this tool, open a private security advisory on GitHub or contact the maintainer directly. Do not open a public issue for something that could be abused before it is fixed.
Please include:
- a short description and the impact
- the affected version or commit
- reproduction steps or a proof of concept
- any suggested fix
You should get an initial reply within a few days.
This project follows a coordinated disclosure model for issues in the tool itself. For issues in WordPress, report them to the WordPress security team or through their HackerOne program.
0xDeathShotX_X - github.com/DeathShotXD