vendor:
Wordpress
by:
Unknown
7.5
CVSS
HIGH
Code Execution
94
CWE
Product Name: Wordpress
Affected Version From: 2.1.2001
Affected Version To: 2.1.2001
Patch Exists: YES
Related CWE:
CPE: a:wordpress:wordpress:2.1.1
Platforms Tested:
2007
WordPress Source Code Compromise
An attacker compromised the source code for Wordpress 2.1.1 and altered it to include a malicious backdoor. This backdoor introduces a code-execution vulnerability that will let remote users inject PHP code or execute operating system commands.
Mitigation:
Upgrade to version 2.1.2 or later