VYPR
Unrated severityNVD Advisory· Published Sep 14, 2007· Updated Jun 16, 2026

CVE-2007-4894

CVE-2007-4894

Description

Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters related to "early database escaping" and missing validation of "query string like parameters."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

33
  • WordPress/WordPress32 versions
    cpe:2.3:a:wordpress:wordpress:0.6.2:*:*:*:*:*:*:*+ 31 more
    • cpe:2.3:a:wordpress:wordpress:0.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:0.6.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:0.71:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.10_rc1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.10_rc2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.1.3_rc1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.1.3_rc2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.2_revision5002:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.2_revision5003:*:*:*:*:*:*:*
    • (no CPE)range: <2.2.3
  • Range: <1.2.5a

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.