CVE-2007-4894: SQL Injection
Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the posttype parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters related to "early database escaping" and missing validation of "query string like parameters."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4894?
CVE-2007-4894 has a high severity level due to its potential for remote SQL injection attacks.
How do I fix CVE-2007-4894?
To fix CVE-2007-4894, upgrade to WordPress version 2.2.3 or later.
Which versions of WordPress are affected by CVE-2007-4894?
CVE-2007-4894 affects all WordPress versions prior to 2.2.3 and WordPress MU versions before 1.2.5a.
What types of attacks can CVE-2007-4894 facilitate?
CVE-2007-4894 can facilitate arbitrary SQL command execution by remote attackers.
Does CVE-2007-4894 affect any plugins or themes?
CVE-2007-4894 specifically targets the WordPress core software and not individual plugins or themes.