Unrated severityNVD Advisory· Published Mar 5, 2007· Updated Jun 16, 2026
CVE-2007-1277
CVE-2007-1277
Description
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:wordpress:wordpress:2.1.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:wordpress:wordpress:2.1.1:*:*:*:*:*:*:*
- (no CPE)range: = 2.1.1
Patches
Vulnerability mechanics
References
10- ifsec.blogspot.com/2007/03/wordpress-code-compromised-to-enable.htmlnvdExploit
- secunia.com/advisories/24374nvdVendor Advisory
- wordpress.org/development/2007/03/upgrade-212/nvdVendor Advisory
- www.kb.cert.org/vuls/id/214480nvdUS Government Resource
- www.kb.cert.org/vuls/id/641456nvdUS Government Resource
- www.securityfocus.com/archive/1/461794/100/0/threadednvd
- www.securityfocus.com/bid/22797nvd
- www.vupen.com/english/advisories/2007/0812nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/32804nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/32807nvd
News mentions
0No linked articles in our index yet.