AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2007-4154

MEDIUM · CVSS 6.5 EPSS 1.90%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-08-03 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2007-4154
Severity
MEDIUM
CVSS
6.5
EPSS
1.90%
WordPress

Original Filing — NVD Description

SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbitrary SQL commands via the page_options parameter to (1) options-general.php, (2) options-writing.php, (3) options-reading.php, (4) options-discussion.php, (5) options-privacy.php, (6) options-permalink.php, (7) options-misc.php, and possibly other unspecified components.