CVE-2007-1277
Status: ModifiedHigh (7.5)—💥 Exploit
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 28%
- Percentile among all scored CVEs: 98
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · WordPress Core 2.1.1 - Arbitrary Command Execution (3/2/2007)
- Published on Exploit-DB · WordPress Core 2.1.1 - '/wp-includes/theme.php?iz' Arbitrary Command Execution (3/2/2007)
Affected technologies (1)
CWEs
- CWE-20
References
- http://ifsec.blogspot.com/2007/03/wordpress-code-compromised-to-enable.html
- http://secunia.com/advisories/24374
- http://wordpress.org/development/2007/03/upgrade-212/
- http://www.kb.cert.org/vuls/id/214480
- http://www.kb.cert.org/vuls/id/641456
- http://www.securityfocus.com/archive/1/461794/100/0/threaded
- http://www.securityfocus.com/bid/22797
- http://www.vupen.com/english/advisories/2007/0812
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32804
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32807
- http://ifsec.blogspot.com/2007/03/wordpress-code-compromised-to-enable.html
- http://secunia.com/advisories/24374
- http://wordpress.org/development/2007/03/upgrade-212/
- http://www.kb.cert.org/vuls/id/214480
- http://www.kb.cert.org/vuls/id/641456
- http://www.securityfocus.com/archive/1/461794/100/0/threaded
- http://www.securityfocus.com/bid/22797
- http://www.vupen.com/english/advisories/2007/0812
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32804
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32807
Raw JSON (NVD)
Show
{
"id": "CVE-2007-1277",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-03-05T20:19:00.000",
"references": [
{
"url": "http://ifsec.blogspot.com/2007/03/wordpress-code-compromised-to-enable.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/24374",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://wordpress.org/development/2007/03/upgrade-212/",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/214480",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/641456",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/461794/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/22797",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/0812",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/32804",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/32807",
"source": "cve@mitre.org"
},
{
"url": "http://ifsec.blogspot.com/2007/03/wordpress-code-compromised-to-enable.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/24374",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://wordpress.org/development/2007/03/upgrade-212/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/214480",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/641456",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/461794/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/22797",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/0812",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/32804",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/32807",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php."
},
{
"lang": "es",
"value": "WordPress 2.1.1, descargado desde algunos sitios de distribución oficial durante febrero y marzo de 2007, contiene una puerta trasera introducida externamente que permite a atacantes remotos ejecutar comandos de su elección mediante (1) una vulnerabilidad de inyección en eval en el parámetro ix de wp-includes/feed.php, y (2) una llamada a passthru no confiable en el parámetro iz de wp-includes/theme.php."
}
],
"lastModified": "2026-06-16T22:37:16.767",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wordpress:wordpress:2.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A7CBC45-320E-48CF-9A63-07DDE2FB61BE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org",
"evaluatorSolution": "This vulnerability is addressed in the following product update:\r\nhttp://wordpress.org/development/2007/03/upgrade-212/"
}