peter bassill · operator
$ cve CVE-2007-1277 JSON

CVE-2007-1277 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 27% (pctl 98)

Patch early

A public exploit exists.

Description

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS27.01% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2007-03-05
Last modified2026-06-16

Affected (1)

VendorProduct
wordpresswordpress

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD