Description
Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as demonstrated using the displayname argument.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2778 Vulnerability (CVE-2019-2778)
WordPress Plugin Meow Gallery (+ Gallery Block) SQL Injection (4.1.8)
WordPress Plugin All-in-One Event Calendar Multiple Vulnerabilities (1.9)
WordPress Plugin WP Mail Logging Security Bypass (1.11.2)
Oracle Database Server Improper Access Control Vulnerability (CVE-2025-50070)