Description
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.
Remediation
References
Related Vulnerabilities
Elgg Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3733)
WordPress Plugin Easy Justified Gallery Cross-Site Scripting (1.0.8)
GlassFish CVE-2018-2911 Vulnerability (CVE-2018-2911)
WordPress Plugin JW Player for Flash & HTML5 Video Cross-Site Request Forgery (2.1.3)