Back

CVE-2005-2108

SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.

Published: Jul 5, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (7)

Vendor Product Version
wordpress wordpress 1.0
wordpress wordpress 1.0.1
wordpress wordpress 1.0.2
wordpress wordpress 1.2
wordpress wordpress 1.5
wordpress wordpress 1.5.1
wordpress wordpress 1.5.1.2

GitHub Security Advisory GHSA-vp6r-rvfq-7qrg

SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 9.32%

Top 5% most likely to be exploited

Threat Score 32.8 / 100

Data Sources

NVD EPSS GitHub