CVE-2007-1897
Publication date 9 April 2007
Last updated 17 July 2025
Ubuntu priority
Description
SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.