Unrated severityNVD Advisory· Published Mar 5, 2007· Updated Apr 23, 2026
CVE-2007-1277
CVE-2007-1277
Description
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.
Affected products
1- cpe:2.3:a:wordpress:wordpress:2.1.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- ifsec.blogspot.com/2007/03/wordpress-code-compromised-to-enable.htmlnvdExploit
- secunia.com/advisories/24374nvdVendor Advisory
- wordpress.org/development/2007/03/upgrade-212/nvdVendor Advisory
- www.kb.cert.org/vuls/id/214480nvdUS Government Resource
- www.kb.cert.org/vuls/id/641456nvdUS Government Resource
- www.securityfocus.com/archive/1/461794/100/0/threadednvd
- www.securityfocus.com/bid/22797nvd
- www.vupen.com/english/advisories/2007/0812nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/32804nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/32807nvd
News mentions
0No linked articles in our index yet.