See how ryan.mcgeary compares to other vendors in security performance
WP-Syntax plugin 0.9.1 and earlier for Wordpress, with registerglobals enabled, allows remote attackers to execute arbitrary PHP code via the testfilter[wphead] array parameter to test/index.php, which is used in a call to the calluserfuncarray function.