CVE-2005-2612
EPSS 38.8%
Description
Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.
How to fix CVE-2005-2612
To remediate CVE-2005-2612, upgrade the affected package to a fixed version below.
- Debian/wordpress—upgrade to 1.5.2-1 or later
Is CVE-2005-2612 being exploited?
Moderate — EPSS is 38.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.5.2-1