vendor:
Wordpress
by:
Unknown
7.5
CVSS
HIGH
Code Execution
Unknown
CWE
Product Name: Wordpress
Affected Version From: 2.1.2001
Affected Version To: 2.1.2001
Patch Exists: YES
Related CWE: Unknown
CPE: a:wordpress:wordpress:2.1.1
Platforms Tested:
Unknown
Code Execution Vulnerability in WordPress 2.1.1
An attacker compromised the source code for Wordpress 2.1.1 and altered it to include a malicious backdoor. This backdoor introduces a code-execution vulnerability that will let remote users inject PHP code or execute operating system commands.
Mitigation:
The vendor recommends that all users who have installed version 2.1.1 upgrade to version 2.1.2 or later.