CVE-2007-0233: High severity WordPress vulnerability
wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tbid parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0233?
CVE-2007-0233 has a high severity rating due to its ability to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2007-0233?
To fix CVE-2007-0233, upgrade your WordPress installation to version 2.0.7 or later.
Which versions of WordPress are affected by CVE-2007-0233?
CVE-2007-0233 affects WordPress versions 2.0.6 and earlier.
Can CVE-2007-0233 lead to data exposure?
Yes, CVE-2007-0233 can lead to unauthorized access and potential data exposure due to SQL injection.
Is my site safe if it's running on WordPress version 2.0.6?
No, if your site is running on WordPress version 2.0.6, it is vulnerable to CVE-2007-0233 and should be updated immediately.