CVE-2005-2612
EPSS 73.4%
Description
Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.
How to fix CVE-2005-2612
To remediate CVE-2005-2612, upgrade the affected package to a fixed version below.
- Debian/wordpress—upgrade to 1.5.2-1 or later
Is CVE-2005-2612 being exploited?
Likely — EPSS is 73.4%, placing CVE-2005-2612 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 1.5.2-1