A file deletion vulnerability that remains unpatched 7 months after being reported allows for the complete takeover of WordPress sites and for arbitrary code execution.
http://feedproxy.google.com/~r/Securityweek/~3/ODFW–9NTZk/unpatched-wordpress-flaw-leads-site-takeover-code-execution










