CVE-2006-2667

WordPress <2.0.2 - Code Injection

Title source: llm

Description

Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as demonstrated using the displayname argument.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/6

Scores

EPSS 0.3219
EPSS Percentile 96.8%

Details

Status published
Products (1)
wordpress/wordpress < 2.0.2
Published May 30, 2006
Tracked Since Feb 18, 2026